New malware uses cookies to break into Google Accounts

Main Image
  • Like
  • Comment
  • Share

A new malware threat known as has emerged, posing a severe risk to Google account security. A report by BleepingComputer says, unlike traditional phishing scams or brute-force attacks, leverages a vulnerability in cookies, making it a more insidious threat. 

This malware especially targets automatic login session cookies, collecting them from Chrome browsers and resurrecting them even after password resets and two-factor authentication. Check out the details.

Malware Exploits Cookies to Hack Google Accounts

Worryingly, even if you change your password or set two-factor authentication, the malware can still provide illegal access, working as a concealed spare key under a floorboard. At the moment, multiple malware groups are exploiting this vulnerability, with some claiming to have adapted to Google’s defenses.

CloudSek researchers successfully reverse-engineered the vulnerability, which was first exposed in October 2023 by a bad actor known as PRISMA. While cookie regeneration only works once after a password reset, regeneration is unlimited, allowing attackers to persist.

Google appears to be actively tackling the issue, as indicated by a malware developer’s attempt to circumvent its safeguards. However, the tech titan has not revealed any details about its efforts to offset any damage. It is critical to avoid installing software from unknown sources to protect against such assaults. If inappropriate behavior is identified on Google Chrome accounts, users should take prompt action.

Here are several important safety precautions:

  1. Update Chrome: To patch the vulnerability, make sure you’re running the most recent version.
  2. Stay Cautious: Caution should be exercised while clicking on suspicious links or downloading unknown applications.
  3. Manual Sign Out: Sign out of your Google account whenever possible, especially on shared computers.
  4. Turn on Strong 2FA: While not perfect, two-factor authentication offers an additional layer of security.
  5. Keep an eye out for security alerts: Keep an eye out for any unusual activity in Google security alerts.

While a permanent solution is being developed, this cookie-based virus serves as a reminder of the ever-changing nature of cyber threats. Users can drastically lower their chances of falling prey to this devious attack by following these recommendations and remaining informed. Remember that online security is a shared responsibility, so be cautious.

You can follow Smartprix on Twitter, Facebook, Instagram, and Google News. Visit smartprix.com for the most recent news, reviews, and tech guides.

Related Articles

ImageMediaTek Dimensity 8450 Launched With All-Big Core Design, Mali-G720 GPU, and Agentic AI Support

The Taiwanese chip manufacturer MediaTek has announced the launch of a new chip: the Dimensity 8450 SoC. It features an all-big core design inspired by MediaTek’s flagship mobile processors, making it 30% faster than competing platforms. The company unveiled the chipset at the India Dimensity Summit. Also Read: Oppo Reno 14 To Launch In India …

ImageLeaked Android certificates left millions of smartphones vulnerable to malware

Looks like millions of Android smartphones were literally inches away from mass malware attacks. Devices from LG, Samsung and MediaTek chipsets were subjected to a major Android vulnerability. Once exploited, it would have given cyberattackers complete authority over your device. In fact, the privileges that this vulnerability introduces to the injected malware may be more …

ImageWhy is Google warning its Users Against Downloading the Bard App? Read Story to Find Out

Leading American Tech giant Google is not a stranger to malware with millions of users affected by the issue on Android. However, in the last few months, Google has been facing a new-age malware challenge that involves Google’s own AI chatbot Bard. Apparently, Google Bard is being misused by scammers to infect malware into users’ …

ImageHow to use Google Quick Share to Transfer Files Even if the Connection Breaks

In 2020, Google launched the Nearby Share feature for Android devices, enabling users to share files seamlessly. Since its inception, Google has enhanced this functionality, rebranding it as Quick Share following its integration with technology created by Samsung. Additionally, the company introduced QR code support to facilitate quicker file transfers. Recently, Google announced a significant …

ImageGoogle Introduces all-new Features for Android & Chrome: Check Out What’s New

Almost all leading technology firms are taking part in Global Accessibility Awareness Day (GAAD) by enhancing the accessibility of their products and services, and Google is no different. This Thursday, Google unveiled two new AI-driven enhancements for Android that build on features previously introduced for the mobile operating system. Updates to Android include Talkback made …

Discuss

1 Comment
Be the first to leave a comment.

Related Products