Article Details

Scrape Timestamp (UTC): 2024-01-03 13:19:01.461

Source: https://thehackernews.com/2024/01/malware-using-google-multilogin-exploit.html

Original Article Text

Click to Toggle View

Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset. Information stealing malware are actively taking advantage of an undocumented Google OAuth endpoint named MultiLogin to hijack user sessions and allow continuous access to Google services even after a password reset. According to CloudSEK, the critical exploit facilitates session persistence and cookie generation, enabling threat actors to maintain access to a valid session in an unauthorized manner. The technique was first revealed by a threat actor named PRISMA on October 20, 2023, on their Telegram channel. It has since been incorporated into various malware-as-a-service (MaaS) stealer families, such as Lumma, Rhadamanthys, Stealc, Meduza, RisePro, and WhiteSnake. The MultiLogin authentication endpoint is primarily designed for synchronizing Google accounts across services when users sign in to their accounts in the Chrome web browser (i.e., profiles). A reverse engineering of the Lumma Stealer code has revealed that the technique targets the "Chrome's token_service table of WebData to extract tokens and account IDs of chrome profiles logged in," security researcher Pavan Karthick M said. "This table contains two crucial columns: service (GAIA ID) and encrypted_token." This token:GAIA ID pair is then combined with the MultiLogin endpoint to regenerate Google authentication cookies. When reached for comment, Google acknowledged the existence of the attack method but noted that users can revoke the stolen sessions by logging out of the impacted browser. "Google is aware of recent reports of a malware family stealing session tokens," the company told The Hacker News. "Attacks involving malware that steal cookies and tokens are not new; we routinely upgrade our defenses against such techniques and to secure users who fall victim to malware. In this instance, Google has taken action to secure any compromised accounts detected." "However, it's important to note a misconception in reports that suggests stolen tokens and cookies cannot be revoked by the user," it further added. "This is incorrect, as stolen sessions can be invalidated by simply signing out of the affected browser, or remotely revoked via the user's devices page. We will continue to monitor the situation and provide updates as needed." The company further recommended users turn on Enhanced Safe Browsing in Chrome to protect against phishing and malware downloads.

Daily Brief Summary

MALWARE // Malware Exploits Google Feature to Bypass Password Resets

Information-stealing malware is exploiting an undocumented Google OAuth endpoint called MultiLogin to maintain unauthorized access to user sessions.

This exploit allows attackers to persist in Google services despite users' passwords being reset, posing a significant threat to account security.

The exploit was disclosed by a hacker on Telegram and has been adopted by various malware-as-a-service (MaaS) families, including Lumma, Rhadamanthys, and others.

By leveraging the MultiLogin feature designed for synchronizing Google accounts, these malwares regenerate authentication cookies using stolen tokens.

Google has acknowledged the attack vector and countered claims that users cannot revoke stolen sessions; signing out or remote revocation is possible.

To enhance security, Google has recommended users enable 'Enhanced Safe Browsing' in Chrome, and they continue to improve defenses against such malware attacks.