Sunday, 24 November 2024
29 C
Singapore

Hackers are stealing passwords in Chrome using the Google sign-in trick

Hackers use a new Chrome attack to steal Google passwords directly from the official sign-in page. Learn how to stay safe.

Cybercriminals have found a new way to steal your passwords in Chrome, and they’re doing it right from the official Google sign-in page. This recent attack uses a sneaky piece of malware known as AutoIt Credential Flusher, which researchers at OALabs discovered. Once you land on the Google sign-in page, the attack traps you, capturing your email and password as you attempt to sign in.

This attack is especially dangerous because it doesn’t redirect you to a fake page. Instead, it abuses a browser feature called “kiosk mode,” making it difficult for you to exit the page. Kiosk mode is a full-screen interface that removes typical browser elements like the address bar and navigation buttons. It’s usually employed for demonstration purposes, such as on a display laptop in a store. Hackers have found a way to use this mode to lock you onto the sign-in page, making you more likely to enter your credentials out of frustration.

How the attack works

In this attack, you’re kept on the legitimate Google sign-in page, but kiosk mode is activated to prevent you from leaving. Normally, you might exit full-screen mode by pressing Esc or F11, but the malware blocks these commands, leaving you trapped. While attempting to sign in, another malware called StealC lurks in the background, waiting to steal your credentials.

The widespread use of Google accounts makes this tactic even more concerning. Many websites and , including popular platforms like Facebook and Digital Trends, offer a Google sign-in option. This means that if a hacker gains access to your Google account, they could quickly gain entry to many other linked accounts.

What to do if you’re caught

If you ever find yourself stuck on the Google sign-in screen and unable to exit, don’t panic. There are a few hotkeys you can try to escape. Using Alt + Tab will let you switch between open windows, which may allow you to close Chrome. Pressing Ctrl + Alt + Delete will bring up Task Manager, where you can force Chrome to close as a process. Another option is to press Alt + F4, which instantly closes the current application. As a last resort, holding down the power button on your computer will shut it down completely.

Once you’ve exited the browser, it’s important to scan your system with antivirus software immediately. For a recommendation, check out some reliable antivirus programs, such as Avast One Gold, for quick and easy protection.

Not just Chrome

Although this attack has mainly targeted Chrome, it’s worth noting that other browsers are also vulnerable. The malware doesn’t discriminate and will attempt to lock any browser on your PC into kiosk mode. This includes Microsoft Edge, the default browser for Windows 11. Fortunately, the hotkey methods mentioned earlier should work no matter which browser is affected.

By staying aware of this new threat and knowing how to respond, you can protect your online security and prevent hackers from stealing your valuable Google credentials.

Hot this week

Anti-deepfake declaration faces scrutiny over possible AI involvement

Minnesota's anti-deepfake law faces controversy as an affidavit supporting it shows signs of AI-generated text with non-existent citations.

New STEM foundation launched at Expand Space to inspire youth in underserved communities

Expand Space 2024 launches a new STEM Foundation to empower underserved youth with hands-on opportunities in Deep Tech, robotics, and AI.

Microsoft to enhance 365 Copilot with AI agents and new features

Microsoft unveils new AI-powered features for 365 Copilot, including Copilot Actions and Windows 365 Link, boosting workplace productivity.

Warrix enhances internal communications with Slack to boost collaboration and efficiency

Warrix has transformed its internal communications with Slack, cutting time spent on meetings and improving collaboration by 30%.

Apple’s Find My will let you share lost item locations with airlines

Apple’s Find My app in iOS 18.2 lets you share lost item locations, helping airlines recover luggage with privacy-focused temporary links.

Tesla and Rivian near settlement in trade secrets dispute

Tesla and Rivian have reached a conditional settlement in their trade secrets lawsuit, potentially resolving the dispute by December 24.

Hyundai recalls over 145,000 EVs in the US over safety concerns

Due to charging unit faults, Hyundai is recalling over 145,000 EVs in the US, including Ioniq and Genesis models. Kia has added 62,000 EV6s to the list.

Bluesky is rising as the next big social network

Bluesky grows rapidly, surpassing 20M users with unique features rivalling Threads and X. Will it become the internet's next big social hub?

Microsoft pauses Windows 11 updates due to issues with Ubisoft games

Due to crashes, Microsoft has paused updating Windows 11 for PCs running Ubisoft games. Affected titles include Assassin's Creed and Star Wars Outlaws.

Related Articles

Popular Categories