logo

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset

ID: 0f12c220-14c8-55f1-bce3-035247e2e028

STIX ID: report--0f12c220-14c8-55f1-bce3-035247e2e028

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-03

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Information-stealing malware families (including Lumma, Rhadamanthys, Stealc, Meduza, RisePro, and WhiteSnake) are abusing an undocumented Google OAuth MultiLogin endpoint to convert GAIA ID + encrypted token pairs extracted from Chrome's WebData token_service into valid Google session cookies, enabling persistent account access even after password resets. The report outlines three token-cookie scenarios, notes that Google can revoke compromised sessions (users can sign out or remove devices), and recommends enabling Enhanced Safe Browsing, changing passwords, and monitoring device activity to mitigate abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.