logo

Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for session hijacking

ID: 28557f1f-bbd8-58c4-84b6-3353511ca4b5

STIX ID: report--28557f1f-bbd8-58c4-84b6-3353511ca4b5

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2023-12-29

Date Updated: 2026-04-27

...
...

CloudSEK researchers detail an active exploit of an undocumented Google OAuth 'MultiLogin' endpoint that allows attackers to regenerate persistent Google service cookies from exfiltrated token:GAIA ID pairs, enabling account persistence even after password resets; the technique was rapidly adopted and blackboxed by multiple infostealer families (Lumma, Rhadamanthys, Stealc, Meduza, RisePro, WhiteSnake) between October–December 2023, with technical analysis showing token theft from Chrome's token_service and Local State decryption and HUMINT corroboration of the exploit's origin and spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.