Malware Leveraging Google Cookie Exploit via OAuth2 Functionality
ID: 16ad00b8-c7e3-5d5a-9564-b86bf4d5c63d
STIX ID: report--16ad00b8-c7e3-5d5a-9564-b86bf4d5c63d
Feed Name: HackRead
Threat Score
CloudSEK researchers disclosed that several malware operators are exploiting an undocumented Google OAuth2 "MultiLogin" endpoint to regenerate authentication cookies and maintain persistent access to Google accounts even after password resets; multiple infostealer families (including Lumma) have integrated this capability, using token/GAIA-ID manipulation, encryption, and proxies to evade detection and sustain session hijacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
