logo

Google: Malware abusing API is standard token theft, not an API issue

ID: e6a02b41-a063-5c78-a569-253b89d97f0b

STIX ID: report--e6a02b41-a063-5c78-a569-253b89d97f0b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-06

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Multiple information-stealing malware families are abusing an undocumented Google Chrome OAuth 'MultiLogin' endpoint to use stolen tokens (including a refresh-like token) to generate new authentication cookies after the originals expire, enabling prolonged unauthorized access to victims' Google accounts; Google views this as cookie-theft rather than a vulnerability and recommends logging out or revoking sessions to mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.