Disclaimer: We sustain our work & review products through paid collaborations.
Hackers Are Using Google.com to Deliver Malware

Hackers Are Using Google.com to Deliver Malware


The security firm C/side discovered a cybersecurity flaw where attackers use Google’s OAuth logout URL to inject malware.

This weaponization of Google OAuth is a new cybersecurity danger that is not only difficult for users to detect but also a challenge for security tools to spot – making this a critical security weakness.

Google search

How is Google.com being used by bad actors?

  • Hackers create a fictitious Google OAuth logout URL that seems legitimate.
  • The Google OAuth logout URL is contained in a script and pulled from an unexpected location.
  • The URL is weaponized with a callback parameter to run an obfuscated JavaScript payload.
  • The unencrypted payload builds a malicious WebSocket link to the hacker’s controlled domain.
  • After a successful WebSocket connection, hackers gain entry to the victim’s browser, allowing them to inject malware into the device.

This cybersecurity threat is especially harmful since it combines domain spoofing with concealed loaders. Therefore, even the most modern and advanced antivirus software will struggle to identify it.

The implications of this type of attack include:

  • Malware distribution
  • Data breach/theft
  • Browser control
  • Financial loss
  • Reputation damage

 

Modernize your device's security

Every day, hackers develop new ways to gain illegitimate access to people’s devices and businesses’ security infrastructure. One common mistake that makes their job easier is undervaluing the need for robust internet security solutions. To ensure you’re protected, there’s nothing like following our recommended cybersecurity steps for everyday users or best practices for small businesses.

Anyone who regularly uses a computer, smartphone, or tablet should always use antivirus software to build a protective wall against imminent cyberthreats.

Sérgio F.
Sérgio F.

From a young age, Sérgio showed a great interest in music and gaming, which served to boost his language skills in the years to come. His connection with creative content started in the early days of his first band, as he was in charge of all written and non-written materials. Later on, to further develop his skills, he studied Communication and Media. He then worked as a content producer, translator, designer, and marketer, until finally taking on the role of Content Creator for Best Reviews. You’ll often find Sérgio writing and producing music, drumming, gaming, going to live shows, and reading about the latest trends in technology.


Best Antivirus software of 2025

Editors' choice

Bitdefender Antivirus Plus

Editor's rating:
Easy to use and personalize
Comprehensive protection tools
Blocks fake and harmful sites
Secures online activity
Browser security

Guardio

Editor's rating:
Stops threats instantly
Tailor settings to your needs
Protects without interruptions
Budget-friendly
Extra security features

Kaspersky Free Anti-Virus

Editor's rating:
Customize your security checks
Stops the newest malware
Secures digital communications
Beginners

AVG Ultimate

Editor's rating:
Easy for anyone to use
All-in-one security solution
Works across your devices
Fair prices

Discussions

Share your thoughts, ask questions, and connect with other users. Your feedback helps our community make better decisions.

©2012-2025 Best Reviews, a clovio brand – All rights reserved