A toolkit created by security researcher Mr.Dox can now let just about anyone create Chrome’s SSO windows for a novel “Browser in the Browser” attack phishing people for their login credentials.
These days, many websites have added login options where users can log in with their Google, Facebook, or other accounts. Doing so launches an additional window called the single sign-on or SSO windows that are stripped down just to a login form and the URL so you’d know you’re on the right page.
Is the browser really your browser?
According to the researchers, users can simply download the templates, edit them to include the desired URL and window title and use an iframe tag to use them in their web pages.
Kuba Gretzky, the creator of the Evilgnix phishing toolkit, also tested out the new method and reported that it works perfectly with the Evilgnix platform, meaning the toolkit can be adapted to steal two-factor authentication keys in phishing attacks.
These types of fake SSO window phishing attacks aren’t new either. Fake gaming sites have previously used them to steal Steam credentials in 2020.
However, now that these templates are freely available, chances are we’ll be seeing a lot more of such attacks. Redteamers can also use them to create phishing pages to test their company’s or client’s defences.
In the News: ApeCoin: Bored Ape Yacht Club’s fresh crypto venture
Someone who writes/edits/shoots/hosts all things tech and when he’s not, streams himself racing virtual cars. You can reach out to Yadullah at [email protected], or follow him on Instagram or Twitter.