logo

Google password resets not enough to stop these info-stealing malware strains

ID: eaeeb583-bdbe-54d4-89f7-a49adb4457b3

STIX ID: report--eaeeb583-bdbe-54d4-89f7-a49adb4457b3

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-01-02

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers warn that several Windows-focused info-stealer malware families (including Lumma and Rhadamanthys) are abusing an undocumented Google OAuth MultiLogin endpoint to harvest Chrome session tokens (token:GAIA ID pairs) and regenerate service cookies to regain access to accounts even after passwords are changed; affected users should fully sign out or revoke affected sessions and remove local malware to invalidate stolen tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.