Sign In
Newsyhub.comNewsyhub.comNewsyhub.com
Notification Show More
Font ResizerAa
  • Home
  • India
    • Bollywood
    • India political news
  • Sports
  • Latest News
  • Around World
  • Technology
  • Movie Review
  • Sports
  • Entertainment
  • About Us
    • Contact
    • Terms of Service
    • Advertise with us
Reading: Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report
Share
Newsyhub.comNewsyhub.com
Font ResizerAa
  • Business
  • Business
  • Politics
  • Politics
  • Travel
  • Travel
  • Entertainment
  • Entertainment
  • Science
  • Science
  • Technology
  • Technology
  • Fashion
  • Fashion
Search
  • Home
  • India
    • Bollywood
    • India political news
  • Sports
  • Latest News
  • Around World
  • Technology
  • Movie Review
  • Sports
  • Entertainment
  • About Us
    • Contact
    • Terms of Service
    • Advertise with us
Have an existing account? Sign In
Follow US
  • Advertise
  • Advertise
© {Year} NewsyHub. Mediora Media Company. All Rights Reserved.
Newsyhub.com > Blog > News > Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report
NewsTechnology

Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report

newyhub
Last updated: 3 January 2024 09:47
newyhub
Share
3 Min Read
Google Responds to Detection of Session Token Malware Capable of Hijacking Accounts: Report
SHARE


Malware designed to steal information from users and hijack their Google accounts is being exploited by multiple malicious groups — even after a password has been reset — according to security researchers. The exploit is reportedly aimed at Windows computers. Once the device is infected, it uses a technique used by “info stealers” to exfiltrate the login session token — assigned to a user’s computer when they log in to their account — and upload it to the cybercriminal’s server.

According to a report published by researchers at CloudSEK, the malware was first launched by threat group PRISMA in October 2023, and uses the search giant’s OAuth endpoint called MultiLogin that is used by Google to allow users to switch between user profiles on the same browser or use multiple login sessions simultaneously. The malware uses auth-login tokens from a user’s Google accounts that are logged in on the computer. The necessary details are decrypted with the help of a key that is stolen from the UserData folder in Windows, as per the report.

Using the stolen login session tokens, malicious users can even regenerate an authentication cookie to log in to a user’s account after it has expired — it can even be reset once, when a user changes their password. As a result, the malware operators can retain access to a user’s account. Threat intelligence group Hudson Rock has provided a demonstration of the flaw being exploited.

 

Meanwhile, BleepingComputer points out that various malware creators have already started to use the exploit to gain access to user data — on November 14, the Lumma stealer was updated to take advantage of the flaw, followed by Rhadamanthys (November 17), Stealc (December 1), Medusa (December 11), RisePro (December 12), and Whitesnake (December 26).

In a statement to 9to5Google, the search giant said that it routinely upgraded its defences against the techniques used by malware, and that compromised accounts detected by the company have been secured.

Google also points out that users can revoke or invalidate the stolen session tokens by either logging out of the browser on a device that has been infected with the malware, or by accessing their devices page in their account settings and remotely sign out of those sessions. Users can also scan their computers for malware and enable the Enhanced Safe Browsing setting in Google Chrome to avoid downloading malware to their computers, according to the company.


Affiliate links may be automatically generated – see our ethics statement for details.
TAGGED:google accountgoogle response malware revive cookies hijack accounts googlemalwareprisma

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Whatsapp Whatsapp Copy Link Print
Share
Previous Article India registered 9.3 lakh cancer deaths, second highest in Asia: LANCET study India registered 9.3 lakh cancer deaths, second highest in Asia: LANCET study
Next Article Aircraft leasing in India picks up: Modair inducts fifth plane | India News Aircraft leasing in India picks up: Modair inducts fifth plane | India News
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Contact Us

Privacy Policy

Cookie Policy

Terms of Use

Advertise with

Newsyhub.comNewsyhub.com
Follow US
© 2025-2026 NewsyHub. Mediora Media Company. All Rights Reserved.
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
[mc4wp_form]
Zero spam, Unsubscribe at any time.