Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » Blogs » Security » Exploit provides access to Google accounts: password change doesn’t help
3 min Security

Exploit provides access to Google accounts: password change doesn’t help

Laura HerijgersJanuary 2, 2024 12:22 pmJanuary 2, 2024
Exploit provides access to Google accounts: password change doesn’t help

Several malware families can give hackers access to Google accounts. For this, the malware abuses an OAuth2 functionality provided by Google. It is not possible to lock out the hacker by changing the password of an affected account.

The Google OAuth2 endpoint MultiLogin would be exploitable for breaking into Google accounts. Through the exploit, hackers steal session cookies, which contain login information. This cookie type remembers the login credentials so that users can access their accounts without entering the username and password each time. It can be used for accessing online services that authenticate you through your Google account.

It involves full authentication, in which two-step verification is bypassed because it is automatically generated from a previous session. Because of the sensitivity of the information contained in these types of cookies, the lifetime of session cookies should be short.

However, MultiLogin allows hackers to recover session cookies from Google. Breaking into a Google account is then possible by using an infostealer malware. Moreover, the exploit automatically generates the latest authentication information. This means the problem is not solved with a password change. That’s not the only problem because hackers can additionally maintain access for a long time. It is an option to re-generate the cookies should the hacker’s open session get interrupted.

Malware for sale online

There are several malware families in circulation, and, according to CloudSEK, there is evidence hackers abuse the exploit. This company’s research team discovered MulitLogin and published a blog with their findings. The evidence that cybercriminals already know about the exploit was actually the beginning point of the research. This came to the knowledge of the researchers through a Telegram message from threat actor “PRISMA”.

In the meantime, six info-stealers malware have already been found. Among the families is the Lumma Infostealer. This type of malware is known for stealing the following sensitive information: crypto wallets, browser extensions and codes for two-step verification. Lumma has been traded since 2022.

Convenience over security?

Google itself did not respond to the discovery and the misuse of MultiLogin has not been officially confirmed. The Hudson Rock team, which also investigates the exploit in another research, says Google is taking no action. They speculate that session cookies will also not be disabled for the sake of ease of use. Google recently released another tool for checking for leaks that expose your password. However, the feature will not be able to detect this specific exploit.

Also read: Google Chrome has Safety Check: controls and needs control

To protect your credentials from cookie theft, it is generally recommended not to use built-in services that save passwords. Otherwise, it is always wise to use such services only if a master password protects the data. In addition, it is recommended to change your settings to delete cookies automatically after closing the browser.

Tags:

exploit / Google / Google Account / infostealer / login credentials / Research

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Google now provides free access to Gemini 2.5 Pro

Google starts deleting inactive accounts

Google adds account synchronisation to its 2FA authenticator app

Google Workspace now alerts key changes to administrator accounts

Editor picks

The technology behind a UEFA Nations League match

Innovation sometimes more exciting than the football

Welcome to exabyte hyperscaler economics 

Exascale object store company MinIO has engineered a new line of AISt...

The AI world is shifting: Microsoft chooses Anthropic, OpenAI opts for Oracle

Where Microsoft and OpenAI were once two peas in a pod, they are now ...

Alphabet reaches milestone of $3 trillion market value

Google parent company Alphabet has reached a market value of $3 trill...

Techzine.tv

Slack is evolving into a work operating system

Slack is evolving into a work operating system

The evolution of HPE from a hardware to a software company

The evolution of HPE from a hardware to a software company

"AI puts process modeling on steroids", SAP's Dee Houchen on business process management

"AI puts process modeling on steroids", SAP's Dee Houchen on business process management

How VMware VCF 9 and Tanzu simplify enterprise automation

How VMware VCF 9 and Tanzu simplify enterprise automation

Read more on Security

Infoblox turns DNS into cybersecurity’s first line of defense
Top story

Infoblox turns DNS into cybersecurity’s first line of defense

Infoblox positions DNS as the earliest point of cyber threat prevention, claiming to block malicious infrastr...

Berry Zwets September 2, 2025
IGEL benefits from seismic VMware and Windows 10 shifts
Top story

IGEL benefits from seismic VMware and Windows 10 shifts

No matter how strong IT security is, cyberattacks are almost impossible to prevent. IGEL argues that endpoint...

Erik van Klinken August 22, 2025
Jaguar Land Rover extends production halt after cyberattack

Jaguar Land Rover extends production halt after cyberattack

Jaguar Land Rover (JLR) has confirmed that the production halt will continue until at least Wednesday, Septem...

Mels Dees 7 hours ago
Wiz launches Incident Response service for cloud security crises

Wiz launches Incident Response service for cloud security crises

Wiz introduces a new service for organizations affected by security incidents. Wiz Incident Response (IR) com...

Berry Zwets 4 hours ago

Expert Talks

The AI productivity mirage: why leaders are aiming at the wrong target

The AI productivity mirage: why leaders are aiming at the wrong target

In the never-ending quest for developer productivity gains, a new def...

Meeting future workload demands: the case for emerging memory technologies

Meeting future workload demands: the case for emerging memory technologies

It often feels as though memory is an outlier in the technology world...

How AI and automation are redefining ROI in the enterprise

Today’s data and business analysts are equipped with a wide array o...

Enhancing video encoding: The AV1 support in the new ARTPEC-9 System-on-Chip

In an era where video security and digital technologies are evolving ...

Tech calendar

VeeamON Tour 2025

September 18, 2025 Driebergen-Rijsenburg

IT Arena

September 26, 2025 Lviv, Ukraine

National 6G Conference

October 7, 2025 Delft

Innovation Week 2025

October 9, 2025 Prague

Luxembourg Venture Days

October 22, 2025 Luxembourg

Appdevcon

March 10, 2026 Amsterdam

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement