Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Lumma malware exposure: restore expired cookies, hijack Google account

Shulou Source: shulou.com Published: 2023-12-24 09:38:22 10月04日 Update

CTOnews.com, Nov. 23 (Xinhua)-- Alon Gal, an expert at cyber security company Hudson Rock, was the first to discover malware called Lumma (aka LummaC2), which was used by hackers to restore expired Google cookie to hijack Google accounts.

Session cookies is a special network cookies in which users ensure that they remain logged in for a period of time. For security reasons, both websites and browsers impose restrictions on the limitation of cookies to avoid abuse.

Lumma malware uses the keys in the recovery file to recover expired cookies (for Google cookies only), but this recovery is limited to once, and each key can be used twice.

Attackers charge a subscription fee of $1000 a month (CTOnews.com Note: currently about 7160 yuan). The malware has not yet been verified by security researchers or Google, but stealer Rhadamanthys announced a similar feature in a recent update.

A few days after contacting Google, Lumma developers released an update claiming it was an additional fix to circumvent new restrictions introduced by Google to prevent cookie recovery.

Tags: Malicious software security personnel key user network update restriction special expert people RMB company function alias remarks diva not yet attacker Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Huawei Shulou Tech Info OPPO Reno Shulou Technology Xiaomi