Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts
ID: 3ed85ca2-43dd-5eb0-9659-6a2b048de96a
STIX ID: report--3ed85ca2-43dd-5eb0-9659-6a2b048de96a
Feed Name: Bleeping Computer
**Executive summary:** Multiple information-stealer malware families are abusing an undocumented Google OAuth "MultiLogin" endpoint to restore expired Google session cookies and maintain persistent access to compromised accounts; CloudSEK and researchers reverse-engineered the technique and show several stealers (Lumma, Rhadamanthys, Stealc, Medusa, RisePro, Whitesnake) have adopted the exploit while Google states it has taken actions to secure compromised accounts and advises removing malware and revoking sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
