logo

Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts

ID: 3ed85ca2-43dd-5eb0-9659-6a2b048de96a

STIX ID: report--3ed85ca2-43dd-5eb0-9659-6a2b048de96a

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2023-12-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Multiple information-stealer malware families are abusing an undocumented Google OAuth "MultiLogin" endpoint to restore expired Google session cookies and maintain persistent access to compromised accounts; CloudSEK and researchers reverse-engineered the technique and show several stealers (Lumma, Rhadamanthys, Stealc, Medusa, RisePro, Whitesnake) have adopted the exploit while Google states it has taken actions to secure compromised accounts and advises removing malware and revoking sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.