Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for session hijacking
ID: 28557f1f-bbd8-58c4-84b6-3353511ca4b5
STIX ID: report--28557f1f-bbd8-58c4-84b6-3353511ca4b5
Feed Name: CloudSEK Blog
CloudSEK researchers detail an active exploit of an undocumented Google OAuth 'MultiLogin' endpoint that allows attackers to regenerate persistent Google service cookies from exfiltrated token:GAIA ID pairs, enabling account persistence even after password resets; the technique was rapidly adopted and blackboxed by multiple infostealer families (Lumma, Rhadamanthys, Stealc, Meduza, RisePro, WhiteSnake) between October–December 2023, with technical analysis showing token theft from Chrome's token_service and Local State decryption and HUMINT corroboration of the exploit's origin and spread.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
