Search

Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report

The zero-day exploit allows malicious users to regenerate an authentication cookie to log in to a user's account, even after a password change.

Advertisement
Highlights
  • Hackers can use stolen session tokens to gain access to a user's account
  • The exploit allows hackers to gain long-term access to Google accounts
  • Users can revoke the sessions by logging out of the affected browser
Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report

Users can enable Enhanced Safe Browsing on Chrome to avoid malware downloads

Photo Credit: Unsplash/ @firmbee

Malware designed to steal information from users and hijack their Google accounts is being exploited by multiple malicious groups — even after a password has been reset — according to security researchers. The exploit is reportedly aimed at Windows computers. Once the device is infected, it uses a technique used by "info stealers" to exfiltrate the login session token — assigned to a user's computer when they log in to their account — and upload it to the cybercriminal's server.

According to a report published by researchers at CloudSEK, the malware was first launched by threat group PRISMA in October 2023, and uses the search giant's OAuth endpoint called MultiLogin that is used by Google to allow users to switch between user profiles on the same browser or use multiple login sessions simultaneously. The malware uses auth-login tokens from a user's Google accounts that are logged in on the computer. The necessary details are decrypted with the help of a key that is stolen from the UserData folder in Windows, as per the report.

Using the stolen login session tokens, malicious users can even regenerate an authentication cookie to log in to a user's account after it has expired — it can even be reset once, when a user changes their password. As a result, the malware operators can retain access to a user's account. Threat intelligence group Hudson Rock has provided a demonstration of the flaw being exploited.

 

Meanwhile, BleepingComputer points out that various malware creators have already started to use the exploit to gain access to user data — on November 14, the Lumma stealer was updated to take advantage of the flaw, followed by Rhadamanthys (November 17), Stealc (December 1), Medusa (December 11), RisePro (December 12), and Whitesnake (December 26).

In a statement to 9to5Google, the search giant said that it routinely upgraded its defences against the techniques used by malware, and that compromised accounts detected by the company have been secured.

Google also points out that users can revoke or invalidate the stolen session tokens by either logging out of the browser on a device that has been infected with the malware, or by accessing their devices page in their account settings and remotely sign out of those sessions. Users can also scan their computers for malware and enable the Enhanced Safe Browsing setting in Google Chrome to avoid downloading malware to their computers, according to the company.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Google, Malware, PRISMA, Google account
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 14 5G With Snapdragon 6 Gen 4 SoC, 6,000mAh Battery Launched
  2. OTT Releases This Week: Jewel Thief, Viduthalai Part 2, and More
  3. OnePlus 12R, Nord 4 and Pad 2 Receiving New OxygenOS 15 Update in India
  4. Vivo X200 Ultra Teased to Get Two Imaging Chips; Camera Samples Revealed
  5. UAE Plans to Launch Digital Dirham, Integrated Wallet in Q4 2025
  6. Vivo X200 Ultra Teased to Get Dedicated Camera Control Button
  7. Corning's Gorilla Glass Cereamic Launched, to Debut on a Motorola Device
  8. Bitcoin Maintains Price at $86,000, Majority Altcoins See Losses
  9. Prince of Persia: The Lost Crown Coming to Android, iOS on This Date
  10. OnePlus President Hints at New Compact Phone; OnePlus 13T Design Leaked
  1. Krafton Acquires Controlling Stake in Real Cricket Developer Nautilus Mobile for Rs. 118 Crore
  2. UAE Plans to Launch Digital Dirham CBDC, Integrated Wallet in Q4 2025
  3. CMF by Nothing Hints at New Products With Pokemon Teasers; CMF Phone 2 Could Launch Soon
  4. Google NotebookLM Upgraded With Mind Maps Feature and Output Language Selector
  5. Ghibli-Themed Tokens Spark Memecoin Frenzy Amid Surge in Anime AI Art Trend on Social Media
  6. Prince of Persia: The Lost Crown to Release on Android, iOS Platforms on April 14
  7. Apple's Foldable iPhone to Sport Display With Same Aspect Ratio as iPad Models, Tipster Claims
  8. Light Phone 3 With OLED Display, 1,800mAh Battery and Minimalist Design Launched: Price, Specifications
  9. Instagram Adopts Popular TikTok Feature, Adds 2X Playback Speed Option for Reels
  10. Anthropic Researchers Make Major Breakthrough In Understanding How an AI Model Thinks
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »