New Credential Theft Technique Targets Browser Users
Marketing · 2024-09-17

New Credential Theft Technique Targets Browser Users

Researchers have uncovered a new tactic employed by hackers to steal user credentials, particularly targeting Google account passwords. This technique, which has been observed since at least August 22, 2024, exploits browser functionality to pressure users into revealing their login information.

The Open Analysis Labs (OALabs) recently published findings detailing this credential theft campaign, which utilizes malware known as StealC. The attack method is notable for its simplicity and effectiveness, relying on user frustration to achieve its goal.

At the core of this technique is the use of kiosk mode, a browser feature typically employed in public terminals. Attackers hijack this functionality to trap users in a full-screen browser window, preventing them from navigating away or closing the application. The only visible element on the screen is a login window, most commonly for Google accounts.

The Credential Flusher, as researchers have dubbed it, is not itself a credential stealer. Instead, it serves as a pressure mechanism, compelling users to enter their login details out of sheer annoyance.

Once the credentials are input, they are stored in the browser's credential store, where they become vulnerable to theft by the StealC malware.

According to intelligence provided by the Loader Insight Agency, the attack typically unfolds in several stages:

  1. The victim's system is initially infected with Amadey, a hacking tool that has been in use for at least six years.
  2. Amadey then loads the StealC malware onto the system.
  3. Next, Amadey deploys the credential flusher.
  4. The credential flusher launches the browser in kiosk mode, trapping the user.
  5. Frustrated, the user enters their login details, which are subsequently stolen by StealC.

The credential flusher is implemented as an AutoIt script, which identifies available browsers on the victim's computer and launches the preferred browser in kiosk mode. It then navigates to the targeted service's login page, typically Google's account login URL.

To prevent users from escaping the trap, the script disables common exit methods such as the ESC and F11 keys. This leaves users with limited options to close the browser or navigate away from the login page.

While this technique primarily targets Google account credentials, the implications extend beyond a single service. Google accounts often serve as a gateway to numerous other services and sensitive information, making them a high-value target for cybercriminals.

In a parallel development, researchers at Cleafy have identified a new variant of the TrickMo banking Trojan. This malware masquerades as the Google Chrome app for Android, adding another layer of complexity to the threat landscape. 

The TrickMo variant employs sophisticated techniques to evade detection and intercept two-factor authentication codes sent via SMS.

As these threats continue to evolve, cybersecurity experts recommend several mitigation strategies:

  1. For users trapped in kiosk mode, alternative keyboard shortcuts like Alt + F4, Ctrl + Shift + Esc, or Ctrl + Alt + Delete may provide an escape route.
  2. Using the Windows Key + R combination to open a command prompt and forcibly terminate the browser process is another option.
  3. In extreme cases, a hard shupown and booting into Safe Mode for a full system scan may be necessary.
  4. To protect against threats like TrickMo, users should only download Android software from the official Google Play Store.

The discovery of these new attack methods underscores the ongoing cat-and-mouse game between cybercriminals and security professionals. 

As hackers develop increasingly sophisticated techniques, users and organizations must remain vigilant and keep their systems updated with the latest security patches.

Cybersecurity agencies, including the U.S. Cybersecurity and Infrastructure Security Agency (CISA), are actively monitoring these threats. CISA has recently added a Microsoft Windows zero-day vulnerability (CVE-2024-43461) in a browser component to its Known Exploitation Catalogue, mandating federal agencies to patch their systems within three weeks.

CVE-2024-43461 was addressed by the latest Patch Tuesday security round-up from Microsoft. However, it has since been updated to zero-day status when it was discovered as already being exploited by the Void Banshee advanced persistent threat group as far back as July 2024. 

The vulnerability itself sits within the MSHTML browser engine, known as Trident, which is used by Microsoft for backward compatibility reasons for Windows users.

CVE-2024-43461 is part of an exploit chain and used in conjunction with a similar vulnerability, CVE-2024-38112, that was fixed in the July 2024 Patch Tuesday updates. These are both remote arbitrary code execution payloads and MSHTML spoofing flaws.

热门文章
PropellerAds 分享了新的 iGaming 案例研究:在 3 个月实现 97,674 次安装和 12,701 笔存款
广告营销
越南在线博彩业政策收紧 催生市场新机遇
东南亚资讯
密西西比州众议院委员会推进提议增加赌场税的法案
游戏风向
超级PAC筹资4800万美元:体育博彩势力加码
游戏风向
菲律宾博彩技术赛道迎来新变局,B2B 供应模式加速渗透
东南亚资讯
哈萨克斯坦计划对在线赌场促销活动进行处罚
游戏风向
巴西拟将博彩税率提高至24% 税收将用于社保和医疗领域
游戏风向
GGC Awards 2026 璀璨科伦坡:致敬 iGaming 行业的领航者与创新力量
灰度头条
BETFAIR 网络攻击80万用户资料泄露
游戏风向
张侨伟参议员排除全面禁止,敦促菲律宾规范网络赌博
东南亚资讯
JILI 宣布与全球板球传奇 AB de Villiers(ABD)达成重磅战略合作
体育游戏
印度最高法院受理公益诉讼,要求全国禁封“伪装”成社交游戏的赌博平台
游戏风向
新泽西州7月博彩收入创6.06亿美元新高,颁布禁令
游戏风向
准备好了将你的收益最大化吗?尝试ProPush.me Constructor!
广告营销
英国确认各垂直行业的赌博税税率
游戏风向
首页
游戏
合作
发现
我的