Malware abusing API is standard token theft, not an API issue

Malware abusing API is standard token theft, not an API issue

Google is downplaying reports of malware abusing an undocumented Google Chrome API to generate new authentication cookies when previously stolen ones have expired.

In late November 2023, BleepingComputer reported on two information-stealing malware operations named Lumma and Rhadamanthys, claiming they could restore expired Google authentication cookies stolen in attacks.


These cookies could then be loaded into threat actors’ browsers to gain access to an infected user’s…


Source link

About search

Check Also

Can Google Give A.I. Answers Without Breaking the Web? – The New York Times

Can Google Give A.I. Answers Without Breaking the Web? – The New York Times

[unable to retrieve full-text content]Can Google Give A.I. Answers Without Breaking the Web?  The New York …

Leave a Reply

Your email address will not be published. Required fields are marked *