Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset
ID: 0f12c220-14c8-55f1-bce3-035247e2e028
STIX ID: report--0f12c220-14c8-55f1-bce3-035247e2e028
Feed Name: The Hacker News
Information-stealing malware families (including Lumma, Rhadamanthys, Stealc, Meduza, RisePro, and WhiteSnake) are abusing an undocumented Google OAuth MultiLogin endpoint to convert GAIA ID + encrypted token pairs extracted from Chrome's WebData token_service into valid Google session cookies, enabling persistent account access even after password resets. The report outlines three token-cookie scenarios, notes that Google can revoke compromised sessions (users can sign out or remove devices), and recommends enabling Enhanced Safe Browsing, changing passwords, and monitoring device activity to mitigate abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
