Cyber Security News

New Phishing Attack Uses Browser-in-the-Browser Technique to Target Gamers

A sophisticated phishing campaign has been uncovered by Silent Push threat analysts, employing the browser-in-the-browser (BitB) technique to target gamers, particularly those playing Counter-Strike 2 on the Steam platform.

This campaign involves creating fake but realistic browser pop-up windows that mimic legitimate login pages, aiming to deceive users into divulging their Steam account credentials.

Example of a website selling Steam accounts with pricing

The attackers are exploiting the brand and identity of the professional eSports team Navi to enhance the credibility of their phishing sites.

Technical Details of the Attack

The BitB attacks are designed to appear as legitimate browser pop-ups, complete with a URL bar that displays the address of the real website, in this case, Steam.

However, these pop-ups are not actual browser windows and cannot be moved or resized outside the main browser frame.

According to the Report, this is a key indicator that can help users identify such phishing attempts.

The attackers have also been promoting their scam domains on platforms like YouTube, further expanding their reach.

The campaign includes websites in English and one in Mandarin, indicating a broad target audience.

Example of the Chinese phishing website in Mandarin with English wording

Impact and Mitigation

The motivation behind targeting Steam accounts is the potential resale value of these accounts, which can contain numerous games and sell for substantial sums.

Websites like playerauctions.com facilitate the sale of such accounts, providing a lucrative market for stolen credentials.

To protect against these attacks, users should be cautious of login pop-ups that cannot be moved or resized.

If a user suspects they have been phished, they should immediately change their account credentials and monitor for any further unauthorized activity.

Silent Push is providing tools and resources to track and mitigate these threats, including a free Community Edition platform that offers advanced threat detection capabilities.

The company is also sharing indicators of future attacks (IOFAs) to help the security community stay ahead of evolving phishing tactics.

As these BitB attacks continue to evolve, it is crucial for gamers and cybersecurity professionals to remain vigilant and adapt their defenses accordingly.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Production Line Camera Flaws Allow Hackers to Disable Recordings

Nozomi Networks Labs has uncovered four severe vulnerabilities in the Inaba Denki Sangyo Co., Ltd.…

2 hours ago

YouTube Creators Targeted by Weaponized Brand Deals Using ‘Clickflix’ Attack Tactic

A new wave of cyberattacks is targeting YouTube creators, leveraging fake brand collaboration offers to…

2 hours ago

Windows MMC Framework Zero-Day Exploited to Execute Malicious Code

Trend Research has uncovered a sophisticated campaign by the Russian threat actor Water Gamayun, exploiting…

3 hours ago

CrushFTP Warns of HTTP(S) Port Vulnerability Enabling Unauthorized Access

Both CrushFTP, a popular file transfer technology, and Next.js, a widely used React framework for…

3 hours ago

Windows 11 24H2 Update Disrupts Connection to Veeam Backup Server

Users of the Veeam Backup Server have encountered a significant issue following the Windows 11…

4 hours ago

Cloudflare Attributes Service Outage to Faulty Password Rotation

Cloudflare experienced a significant service outage that affected several of its key offerings, including R2…

4 hours ago