Skip Navigation

Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts

www.bleepingcomputer.com Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts

Multiple information-stealing malware families are abusing an undocumented Google OAuth endpoint named "MultiLogin" to restore expired authentication cookies and log into users' accounts, even if an account's password was reset.

Malware abuses Google OAuth endpoint to ‘revive’ cookies, hijack accounts
4