logo

Attackers Abuse Google OAuth Endpoint to Hijack User Sessions

ID: 88ee682a-0faf-5e0d-99a0-b2ee61165d21

STIX ID: report--88ee682a-0faf-5e0d-99a0-b2ee61165d21

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-01-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

CloudSEK researchers uncovered that a threat actor named 'Prisma' disclosed an exploit abusing an undocumented Google OAuth "MultiLogin" endpoint, allowing generation of persistent authentication cookies and session hijacking that remain effective after password resets; multiple infostealer families (Lumma, Rhadamanthys, Risepro, Meduza, Stealc Stealer, White Snake) have adopted and enhanced the technique, using encrypted payloads and SOCKS proxies to evade detection and IP restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.