Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for session hijacking
Category: Adversary IntelligenceIndustry: All IndustriesMotivation:FinancialSource*: C - Fairly Reliable1 - Confirmed by Independent sourcesExecutive SummaryIn October 2023, PRISMA, a developer, uncovered a critical exploit that allows the generation of persistent Google cookies through token manipulation. This exploit enables continuous access to Google services, even after a user's password reset. A client, a threat actor, later reverse-engineered this script and incorporated it into Lumma...
Read more at cloudsek.com