Ayaksız
  • Anasayfa
  • Typography
  • Blog
  • Text Ticker
  • Video Playlist
  • Click to open the search input field Click to open the search input field Ara
  • Menu Menu
Blog - En Güncel Haberler
Buradasınız: Anasayfa1 / Blog2 / Tech3 / Google Acknowledges Discovery of Session Token Malware with Account Hijacking...

Google Acknowledges Discovery of Session Token Malware with Account Hijacking Capabilities: Report

Ocak 3, 2024/in Tech/tarafından ayaksız

The zero-day exploit enables malicious users to regenerate an authentication cookie, providing unauthorized access to a user’s account even after a password change.

Malware designed to steal information from users and hijack their Google accounts is being exploited by multiple malicious groups — even after a password has been reset — according to security researchers. The exploit is reportedly aimed at Windows computers. Once the device is infected, it uses a technique used by “info stealers” to exfiltrate the login session token — assigned to a user’s computer when they log in to their account — and upload it to the cybercriminal’s server.

According to a report published by researchers at CloudSEK, the malware was first launched by threat group PRISMA in October 2023, and uses the search giant’s OAuth endpoint called MultiLogin that is used by Google to allow users to switch between user profiles on the same browser or use multiple login sessions simultaneously. The malware uses auth-login tokens from a user’s Google accounts that are logged in on the computer. The necessary details are decrypted with the help of a key that is stolen from the UserData folder in Windows, as per the report.

Using the stolen login session tokens, malicious users can even regenerate an authentication cookie to log in to a user’s account after it has expired — it can even be reset once, when a user changes their password. As a result, the malware operators can retain access to a user’s account. Threat intelligence group Hudson Rock has provided a demonstration of the flaw being exploited.

Meanwhile, BleepingComputer points out that various malware creators have already started to use the exploit to gain access to user data — on November 14, the Lumma stealer was updated to take advantage of the flaw, followed by Rhadamanthys (November 17), Stealc (December 1), Medusa (December 11), RisePro (December 12), and Whitesnake (December 26).

In a statement to 9to5Google, the search giant said that it routinely upgraded its defences against the techniques used by malware, and that compromised accounts detected by the company have been secured.

Google emphasizes that users can mitigate the risk posed by the stolen session tokens by either logging out of the browser on the infected device or remotely signing out of those sessions through the devices page in their account settings. Additionally, users are advised to conduct malware scans on their computers and activate the Enhanced Safe Browsing setting in Google Chrome to prevent malware downloads. These actions collectively contribute to enhancing the security of users’ accounts.

Etiketler: Google, Google account, Malware, PRISMA
https://ayaksiz.net/wp-content/uploads/2024/01/macosi_firmbee_unsplash_1700656946962.webp 534 950 ayaksız https://ayaksiz.net/wp-content/uploads/2025/12/ayaksiz-net-logo-286x300.png ayaksız2024-01-03 20:49:132024-01-03 20:49:13Google Acknowledges Discovery of Session Token Malware with Account Hijacking Capabilities: Report
Beğenebilecekleriniz:
Android 16 Beta 4 Update Brings New Clock Font and Dynamic AOD Colours to Pixel Devices
Gemini AI Set to Make Google Maps a Conversational Travel Companion
TikTok to Allow US Android Users to Download App Directly from Website via Kits
Report: Google’s AI-Powered Search Generative Experience May Be Offered Through Paid Subscription
Google Experiments with Verified Check Marks in Search Results to Highlight Trusted Sources
Report: Google Pixel Watch 3 Set to Launch in 45mm Size, Pixel Buds Pro 2 Under Development
YouTube Shorts Enhances Dream Screen AI with Video Background Generation Feature
TikTok Users in Limbo as App’s Return to U.S. Stores Faces Legal Delays

Sayfalar

  • Blog
  • Home
  • Text Ticker
  • Typography
  • Video Playlist

Kategoriler

  • Business
  • Devices
  • Gadgets
  • Hot News
  • Science
  • Startups
  • Tech

Arşiv

  • Nisan 2026
  • Mart 2026
  • Şubat 2026
  • Ocak 2026
  • Aralık 2025
  • Kasım 2025
  • Ekim 2025
  • Eylül 2025
  • Ağustos 2025
  • Temmuz 2025
  • Haziran 2025
  • Mayıs 2025
  • Nisan 2025
  • Mart 2025
  • Şubat 2025
  • Ocak 2025
  • Aralık 2024
  • Kasım 2024
  • Ekim 2024
  • Eylül 2024
  • Ağustos 2024
  • Temmuz 2024
  • Haziran 2024
  • Mayıs 2024
  • Nisan 2024
  • Mart 2024
  • Şubat 2024
  • Ocak 2024
  • Aralık 2023
  • Mayıs 2018
  • Şubat 2018
  • Aralık 2017
  • Kasım 2017

İlgi çekici linkler

Here are some interesting links for you! Enjoy your stay :)

Sayfalar

  • Blog
  • Home
  • Text Ticker
  • Typography
  • Video Playlist

Kategoriler

  • Business
  • Devices
  • Gadgets
  • Hot News
  • Science
  • Startups
  • Tech

Arşiv

  • Nisan 2026
  • Mart 2026
  • Şubat 2026
  • Ocak 2026
  • Aralık 2025
  • Kasım 2025
  • Ekim 2025
  • Eylül 2025
  • Ağustos 2025
  • Temmuz 2025
  • Haziran 2025
  • Mayıs 2025
  • Nisan 2025
  • Mart 2025
  • Şubat 2025
  • Ocak 2025
  • Aralık 2024
  • Kasım 2024
  • Ekim 2024
  • Eylül 2024
  • Ağustos 2024
  • Temmuz 2024
  • Haziran 2024
  • Mayıs 2024
  • Nisan 2024
  • Mart 2024
  • Şubat 2024
  • Ocak 2024
  • Aralık 2023
  • Mayıs 2018
  • Şubat 2018
  • Aralık 2017
  • Kasım 2017
© Telif Hakkı - Ayaksız - powered by Enfold WordPress Theme
Link to: CoinDCX Denies Allegations of Fraud Probe Amidst Ongoing Turmoil in India’s Crypto Sector Link to: CoinDCX Denies Allegations of Fraud Probe Amidst Ongoing Turmoil in India’s Crypto Sector CoinDCX Denies Allegations of Fraud Probe Amidst Ongoing Turmoil in India’s... Link to: Moto G34 5G Set to Launch in India on January 9; Exclusive Availability on Flipkart Link to: Moto G34 5G Set to Launch in India on January 9; Exclusive Availability on Flipkart Moto G34 5G Set to Launch in India on January 9; Exclusive Availability on ...
Sayfanın başına dön Sayfanın başına dön Sayfanın başına dön