HomeSecurityHackers steal Steam credentials via Browser-in-the-Browser phishing attacks

Hackers steal Steam credentials through Browser-in-the-Browser phishing attacks

Hackers are stealing credentials for Steam accounts using a Browser-in-the-Browser phishing technique that is becoming increasingly popular among cybercriminals.

The Browser-in-the-Browser technique is a relatively new attack that involves creating fake browser windows within the active window, and making them appear as a pop-up login/login page for a targeted service.

Browser-in-the-Browser phishing

In March 2022, BleepingComputer was the first to report on the capabilities of this new phishing kit created by security mr.d0x. Using this phishing kit, some hackers are creating fake login forms for Steam, Microsoft, Google, and any other service.

See also: Apple fixes zero-day bug affecting iPhone and Mac

Researchers at Group-IB have published a new report on attacks using this Browser-in-the-Browser phishing technique, specifically referring to a new campaign targeting Steam users and mainly professional gamers.

The hackers' goal is to steal the credentials for these Steam accounts and then sell access to the accounts. Some prominent Steam accounts are valued at between $100,000 and $300,000.

Group-IB reports that the phishing kit used in this particular campaign targeting Steam users is not widely available on hacking forums or dark web marketplaces. Instead, it is used privately by hackers who gather on Discord or Telegram channels to coordinate their attacks.

Potential victims are targeted via direct messages on Steam. Hackers invite them to join a team for LoL, CS, Dota 2, or PUBG tournaments.

Hackers steal Steam credentials through Browser-in-the-Browser phishing attacks
Hackers steal Steam credentials through Browser-in-the-Browser phishing attacks

The attackers then send links to the victims, which take the targets to a phishing site, which appears to be an organization that sponsors and hosts esports competitions.

To join a team and play in a competition, targets are asked to log in via their Steam account. However, the new login page window is not a real browser window on top of the existing website, but a fake window created on the current page. This, however, cannot be understood by the user.

See also: U-Haul reveals data breach – driver's licenses exposed

The hackers have done a very careful job, since the pages support 27 languages ​​and use the appropriate one, detecting the language from the victim's browser preferences.

Once the victim enters their Steam account credentials, a new form prompts them to enter their 2FA code. If the second step is unsuccessful, an error message is displayed. If authentication is successful, the user is redirected to a URL specified by the C2. Typically, this is a legitimate address, to minimize the chances of the victim realizing the breach.

After this step, the victim's credentials have already been stolen and sent to the hackers. In similar attacks, the perpetrators quickly compromise Steam accounts, changing passwords and email addresses to make it harder for victims to regain control of their accounts.

Steam hackers

How to spot a Browser-in-the-Browser phishing attack?

In all Browser-in-the-Browser phishing attacks, the URL in the phishing window is the legitimate one, as hackers are free to display whatever they want, since it is not a browser window but simply a render.

The same goes for the SSL certificate symbol, which indicates an HTTPS connection, creating a false sense of security.

See also: Cisco confirms Yanluowang ransomware leaked its data

The phishing kit also allows users to drag the fake window, minimize, maximize, and close it, making it very difficult to detect as a fake browser-in-the-browser window.

Since the technique requires JavaScript, aggressively blocking JS scripts will prevent the fake login from occurring. However, most people don't block scripts, as they would have problems on many popular websites.

Therefore, you should be very careful with the messages you receive on Steam, Discord, or other gaming -related platforms and avoid following links sent by users you don't know.

More details about the new Browser-in-the-Browser phishing and Steam account theft can be found in the Group-IB report.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS