Halil, the “MFA bypass” claim needs narrowing. FACT: AmnesiaStealer copies Chromium Cookies, Login Data, Local Storage, Session Storage, IndexedDB, Local State, and related profile files, recovers the browser Safe Storage key, then remotely drives the cloned authenticated browser. ASSESSMENT: that is session hijacking—reusing an authorization result—not defeating WebAuthn, push, or another MFA verifier. SynkLoader’s documented PhishLocker captures the Windows password; reporting does not demonstrate that it defeats a second factor. Its reverse proxy may preserve trusted-network context, but that alone is not MFA bypass.
After a password reset, exported cookies, access or refresh tokens stored in browser data, federated service-provider sessions, and the attacker’s profile clone may remain usable until the issuing service invalidates them. After a routine single-session revocation, the password, other sessions, refresh tokens outside that revocation scope, third-party OAuth grants, and independent relying-party sessions may remain. SynkLoader’s stolen password itself becomes invalid after reset, but any sessions or persistence created with it beforehand do not necessarily disappear. UNKNOWN: current reporting does not establish theft of passkey private keys, device certificates, Kerberos tickets, app passwords, API keys, or newly enrolled authentication methods.
I would classify an identity as persistently compromised if telemetry shows successful activity after global revocation, refresh-token redemption or new token issuance after containment, unexplained OAuth consent or authentication-method enrollment, surviving relying-party sessions, or use from the infected device through its proxy. Endpoint findings are equally decisive: Amnesia’s cloned-profile directory or continuing control channel, or SynkLoader’s scheduled task, reverse proxy, VNC, or remote PowerShell capability. An infected endpoint can simply capture the replacement credential or a newly authenticated session.
Tonight’s order is: (1) isolate affected endpoints while preserving memory, browser, IdP, Teams, proxy, and endpoint evidence; (2) disable affected identities and revoke IdP sessions, refresh tokens, OAuth grants, device trust, and downstream application sessions—not merely passwords; (3) rotate passwords and other credentials from a clean device, remove unknown authentication methods, and re-register phishing-resistant WebAuthn credentials; (4) reimage infected systems and invalidate browser/keychain material; (5) restore access gradually under compliant-device and risk-based controls while hunting for post-revocation token use. Passkeys prevent credential phishing, but they cannot make an already-compromised browser session trustworthy.