Hackers are stealing credentials for Steam accounts using a Browser-in-the-Browser phishing technique that is becoming increasingly popular among cybercriminals.
The Browser-in-the-Browser technique is a relatively new attack that involves creating fake browser windows within the active window, and making them appear as a pop-up login/login page for a targeted service.

In March 2022, BleepingComputer was the first to report on the capabilities of this new phishing kit created by security mr.d0x. Using this phishing kit, some hackers are creating fake login forms for Steam, Microsoft, Google, and any other service.
See also: Apple fixes zero-day bug affecting iPhone and Mac
Researchers at Group-IB have published a new report on attacks using this Browser-in-the-Browser phishing technique, specifically referring to a new campaign targeting Steam users and mainly professional gamers.
The hackers' goal is to steal the credentials for these Steam accounts and then sell access to the accounts. Some prominent Steam accounts are valued at between $100,000 and $300,000.
Group-IB reports that the phishing kit used in this particular campaign targeting Steam users is not widely available on hacking forums or dark web marketplaces. Instead, it is used privately by hackers who gather on Discord or Telegram channels to coordinate their attacks.
Potential victims are targeted via direct messages on Steam. Hackers invite them to join a team for LoL, CS, Dota 2, or PUBG tournaments.

The attackers then send links to the victims, which take the targets to a phishing site, which appears to be an organization that sponsors and hosts esports competitions.
To join a team and play in a competition, targets are asked to log in via their Steam account. However, the new login page window is not a real browser window on top of the existing website, but a fake window created on the current page. This, however, cannot be understood by the user.
See also: U-Haul reveals data breach – driver's licenses exposed
The hackers have done a very careful job, since the pages support 27 languages and use the appropriate one, detecting the language from the victim's browser preferences.
Once the victim enters their Steam account credentials, a new form prompts them to enter their 2FA code. If the second step is unsuccessful, an error message is displayed. If authentication is successful, the user is redirected to a URL specified by the C2. Typically, this is a legitimate address, to minimize the chances of the victim realizing the breach.
After this step, the victim's credentials have already been stolen and sent to the hackers. In similar attacks, the perpetrators quickly compromise Steam accounts, changing passwords and email addresses to make it harder for victims to regain control of their accounts.

How to spot a Browser-in-the-Browser phishing attack?
In all Browser-in-the-Browser phishing attacks, the URL in the phishing window is the legitimate one, as hackers are free to display whatever they want, since it is not a browser window but simply a render.
The same goes for the SSL certificate symbol, which indicates an HTTPS connection, creating a false sense of security.
See also: Cisco confirms Yanluowang ransomware leaked its data
The phishing kit also allows users to drag the fake window, minimize, maximize, and close it, making it very difficult to detect as a fake browser-in-the-browser window.
Since the technique requires JavaScript, aggressively blocking JS scripts will prevent the fake login from occurring. However, most people don't block scripts, as they would have problems on many popular websites.
Therefore, you should be very careful with the messages you receive on Steam, Discord, or other gaming -related platforms and avoid following links sent by users you don't know.
More details about the new Browser-in-the-Browser phishing and Steam account theft can be found in the Group-IB report.
Source: www.bleepingcomputer.com
