logo

Malware Leveraging Google Cookie Exploit via OAuth2 Functionality

ID: 16ad00b8-c7e3-5d5a-9564-b86bf4d5c63d

STIX ID: report--16ad00b8-c7e3-5d5a-9564-b86bf4d5c63d

Feed Name: HackRead

Threat Score
80/100

Date Published: 2023-12-29

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

CloudSEK researchers disclosed that several malware operators are exploiting an undocumented Google OAuth2 "MultiLogin" endpoint to regenerate authentication cookies and maintain persistent access to Google accounts even after password resets; multiple infostealer families (including Lumma) have integrated this capability, using token/GAIA-ID manipulation, encryption, and proxies to evade detection and sustain session hijacking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.