Google Chrome users on Windows should immediately disable automatic downloads in the browser to protect their authentication data from a newly discovered threat.
The Chrome browser is currently the most popular browser on desktop devices. It is configured to automatically transfer secure files to the user's system without prompting by default.
Any file downloaded by Google Chrome users goes through Google's Safe Browsing checks to be automatically transferred to the default download folder.
The new attack, detailed on the Defense Code website, exploits Google Chrome's auto-download behavior with Windows Explorer shell script files that have the .scf file extension.
The malicious script comes in the form of plain text that includes instructions, and limited commands. What's interesting is that it can load resources from a remote server.
Even more problematic is the fact that Windows will process these files as soon as you open the folder they are stored in, and that these files appear without an extension in Windows Explorer regardless of settings. This means that attackers could easily hide the file behind a disguised filename, such as .jpg.
Attackers use an SMB server location for the icon. What happens next is that the server requests authentication and the system will provide it. The researchers note that cracking passwords is now a game, unless they are complex.
The situation is even worse for Windows 8 or 10 users who authenticate with a Microsoft account, as the account would give the attacker access to online services like Outlook, OneDrive, or Office 365, if the user uses them. There is also the possibility of the password being reused on non-Microsoft websites.
