Attackers Abuse Google OAuth Endpoint to Hijack User Sessions
ID: 88ee682a-0faf-5e0d-99a0-b2ee61165d21
STIX ID: report--88ee682a-0faf-5e0d-99a0-b2ee61165d21
Feed Name: Dark Reading
Date Published: 2024-01-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
CloudSEK researchers uncovered that a threat actor named 'Prisma' disclosed an exploit abusing an undocumented Google OAuth "MultiLogin" endpoint, allowing generation of persistent authentication cookies and session hijacking that remain effective after password resets; multiple infostealer families (Lumma, Rhadamanthys, Risepro, Meduza, Stealc Stealer, White Snake) have adopted and enhanced the technique, using encrypted payloads and SOCKS proxies to evade detection and IP restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
