Latest News
  • The Pixel 10 might get a big charging upgrade (Qi2 aside)
  • Access Denied
  • Access Denied
  • Access Denied
  • Access Denied
  • Access Denied
  • Android phones have a backup problem, but Google could be about to fix it
  • Google officially reveals full Pixel 10 and Pixel Watch 4 designs in new trailer
  • Access Denied
  • Access Denied
Surakshit Bharat

Technology and Cyber News

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
Google Responds to Session Token Malware That Can Hijack Your Accounts
Technology03/01/2024

Google Responds to Session Token Malware That Can Hijack Your Accounts



Malware designed to steal information from users and hijack their Google accounts is being exploited by multiple malicious groups — even after a password has been reset — according to security researchers. The exploit is reportedly aimed at Windows computers. Once the device is infected, it uses a technique used by “info stealers” to exfiltrate the login session token — assigned to a user’s computer when they log in to their account — and upload it to the cybercriminal’s server.

According to a report published by researchers at CloudSEK, the malware was first launched by threat group PRISMA in October 2023, and uses the search giant’s OAuth endpoint called MultiLogin that is used by Google to allow users to switch between user profiles on the same browser or use multiple login sessions simultaneously. The malware uses auth-login tokens from a user’s Google accounts that are logged in on the computer. The necessary details are decrypted with the help of a key that is stolen from the UserData folder in Windows, as per the report.

Using the stolen login session tokens, malicious users can even regenerate an authentication cookie to log in to a user’s account after it has expired — it can even be reset once, when a user changes their password. As a result, the malware operators can retain access to a user’s account. Threat intelligence group Hudson Rock has provided a demonstration of the flaw being exploited.

 

Meanwhile, BleepingComputer points out that various malware creators have already started to use the exploit to gain access to user data — on November 14, the Lumma stealer was updated to take advantage of the flaw, followed by Rhadamanthys (November 17), Stealc (December 1), Medusa (December 11), RisePro (December 12), and Whitesnake (December 26).

In a statement to 9to5Google, the search giant said that it routinely upgraded its defences against the techniques used by malware, and that compromised accounts detected by the company have been secured.

Google also points out that users can revoke or invalidate the stolen session tokens by either logging out of the browser on a device that has been infected with the malware, or by accessing their devices page in their account settings and remotely sign out of those sessions. Users can also scan their computers for malware and enable the Enhanced Safe Browsing setting in Google Chrome to avoid downloading malware to their computers, according to the company.


Affiliate links may be automatically generated – see our ethics statement for details.



Source link

TAGS: google accountgoogle response malware revive cookies hijack accounts googlemalwareprisma

Related posts

Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied
Access Denied

Recent Posts

  • The Pixel 10 might get a big charging upgrade (Qi2 aside)
  • Access Denied
  • Access Denied
  • Access Denied
  • Access Denied

Recent Comments

  • ufattlok on Xbox Cloud Gaming hits PC and iOS soon
  • oborudovaniye_peregovornykh_qqkn on Xbox Cloud Gaming hits PC and iOS soon
  • bestiptv-smarters on Epic’s never-ending Fortnite lawsuits are exhausting
  • bestiptv-smarters on Best Deals on ACs, Washing Machines and Refrigerators During Amazon Sale
  • bestiptv-smarters on There’s an even better Galaxy Z Fold 6 coming, but you can’t have it

Main Menu

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

Leave a reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Arts & Entertainment, Celebrities
  • Arts & Entertainment, Photography
  • Business, Advertising
  • Business, Article Marketing
  • Business, Careers
  • Business, Customer Service
  • Business, Entrepreneurs
  • Business, Marketing
  • Business, Sales
  • Business, Small Business
  • Communications, GPS
  • Communications, Video Conferencing
  • Computers, Computer Certification
  • Computers, Data Recovery
  • Computers, Games
  • Computers, Hardware
  • Cyber Security
  • Digital Marketing Las Vegas
  • Disease & Illness, Breast Cancer
  • Fashion, Clothing
  • Finance, Credit
  • Finance, Currency Trading
  • Finance, Insurance
  • Finance, Investing
  • Finance, Personal Finance
  • Finance, Real Estate
  • Finance, Taxes
  • Food & Beverage, Coffee
  • Food & Beverage, Cooking
  • Food & Beverage, Gourmet
  • furniture, home improvement, babies toddler, home and family, business, back pain, health and fitness, sleep snoring, interior design and decorating, shopping and product reviews, pest control
  • Health & Fitness, Acne
  • Health & Fitness, Alternative Medicine
  • Health & Fitness, Beauty
  • Health & Fitness, Cardio
  • Health & Fitness, Depression
  • Health & Fitness, Diabetes
  • Health & Fitness, Exercise
  • Health & Fitness, Fitness Equipment
  • Health & Fitness, Medicine
  • Health & Fitness, Weight Loss
  • Home & Family, Gardening
  • Home & Family, Hobbies
  • Home & Family, Holidays
  • Home & Family, Home Improvement
  • Home & Family, Home Security
  • Home & Family, Parenting
  • Home & Family, Pets
  • Internet Business, Audio-Video Streaming
  • Internet Business, Blogging
  • Internet Business, Domains
  • Internet Business, Ebooks
  • Internet Business, Ecommerce
  • Internet Business, Email Marketing
  • Internet Business, Ezine Publishing
  • Internet Business, Podcasts
  • Internet Business, Security
  • Internet Business, SEO
  • Internet Business, Site Promotion
  • Internet Business, Web Design
  • mobiles
  • Politics, Commentary
  • Politics, Current Events
  • Product Reviews, Book Reviews
  • Product Reviews, Music Reviews
  • Recreation & Sports, Biking
  • Recreation & Sports, Fishing
  • Recreation & Sports, Martial Arts
  • Reference & Education, College
  • Reference & Education, Environmental
  • Reference & Education, Homeschooling
  • Reference & Education, K-12 Education
  • Reference & Education, Language
  • Reference & Education, Legal
  • Reference & Education, Science
  • Reference & Education, Sociology
  • Self Improvement, Attraction
  • Self Improvement, Coaching
  • Self Improvement, Creativity
  • Self Improvement, Happiness
  • Self Improvement, Success
  • Self Improvement, Time Management
  • Society, Divorce
  • Society, Marriage
  • Society, Relationships
  • Society, Religion
  • Society, Sexuality
  • Society, Weddings
  • Technology
  • Travel & Leisure, Aviation
  • Travel & Leisure, Boating
  • Travel & Leisure, Destinations
  • Travel & Leisure, Outdoors
  • Travel & Leisure, Travel Tips
  • Travel & Leisure, Vacations
  • Uncategorized
  • Vehicles, Boats
  • Vehicles, Cars
  • Writing & Speaking, Writing

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021

Search

Go Up
© 2025 Newspaper-X a theme by Colorlib
  • Home
  • About Us
  • Contact Us
  • Privacy Policy