OLV Basiliek Zwolle

Main Menu

  • Home
  • Browser list
  • Browser software
  • Browser types
  • Browser news

OLV Basiliek Zwolle

Header Banner

OLV Basiliek Zwolle

  • Home
  • Browser list
  • Browser software
  • Browser types
  • Browser news
Browser types
Home›Browser types›New phishing kit makes it easier to tamper with Chrome browser windows

New phishing kit makes it easier to tamper with Chrome browser windows

By Ronnie A. Huntsman
March 22, 2022
0
0

Ever wanted to become a phisher? It’s easier than ever with a new downloadable kit.

The phishing kit allows anyone to download the templates needed to create fake versions of single sign-on login forms – the mini browser windows that pop up to allow users to log in to a third-party site with their accounts on services such as Google, Apple or Twitter.

Not only are these phishing browsers easy to create, but they are also incredibly difficult to spot and could fool even an experienced tech who could easily spot most other phishing schemes.

How it works

The kit was created by a security researcher, mr.d0x, who published it on GitHub. The researcher referred to the new form of phishing attack as a “Browser in the Browser” (BitB) attack.

Models in the kit include Google Chrome for Windows and Mac, with dark and light mode versions available.

Phishers will still have to lure a victim to a fake login page, but once they click the button to login, they’ll see an image rendered with custom HTML and CSS to look like a browser popup.

Oh That’s Bad: Browser In The Browser (BITB) Attack, a new phishing technique that steals credentials that even a web professional can’t detect. #Security https://t.co/cxU83DMezt pic.twitter.com/m9eYOmq0al

— François Zaninotto 🇺🇦 (@francoisz) March 18, 2022

URL extraction

A big part of what makes this trick so compelling is that the URL — the place cybersecurity training tells everyone to check for misspellings or hidden custom subdomains — can be forged.

The apparent browser popup is not actually a real popup, so the URL can say whatever the phisher wants.

How convincing are they? Looked.

Categories

  • Browser list
  • Browser news
  • Browser software
  • Browser types

Recent Posts

  • Best Browser-Based Image Editors of May 2022
  • DuckDuckGo Privacy Browser app does not block Microsoft trackers
  • Best Maps and Navigation Extension for Chrome Browser of 2022 May
  • Best Sports Extension for Chrome Browser of May 2022
  • DuckDuckGo’s supposedly private browser caught allowing ad tracking

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • Privacy Policy
  • Terms and Conditions