Google password resets not enough to stop these info-stealing malware strains
ID: eaeeb583-bdbe-54d4-89f7-a49adb4457b3
STIX ID: report--eaeeb583-bdbe-54d4-89f7-a49adb4457b3
Feed Name: The Register (Security)
Threat Score
Security researchers warn that several Windows-focused info-stealer malware families (including Lumma and Rhadamanthys) are abusing an undocumented Google OAuth MultiLogin endpoint to harvest Chrome session tokens (token:GAIA ID pairs) and regenerate service cookies to regain access to accounts even after passwords are changed; affected users should fully sign out or revoke affected sessions and remove local malware to invalidate stolen tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
