Malware locks browser in kiosk mode to steal Google credentials

Teilen:

A malware campaign uses the unusual method of locking users in their browser’s kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware.

Specifically, the malware “locks” the user’s browser on Google’s login page with no obvious way to close the window, as the malware also blocks the “ESC” and “F11” keyboard keys. The goal is to frustrate the user enough that they enter and save their Google credentials in the browser to “unlock” the computer.

Once credentials are saved, the StealC information-stealing malware steals them from the credential store and sends them back to the attacker.

Kiosk mode theft

Nach Angaben von OALABS researchers who uncovered this peculiar attack method, it has been used in the wild since at least August 22, 2024, mainly by Amadey, a malware loader, info-stealer, and system reconnaissance tool first deployed by hackers in 2018.

When launched, Amadey will deploy an AutoIt script that acts as the credentials flusher, which scans the infected machine for available browsers and launches one in kiosk mode to a specified URL.

Script part that launches Chrome or Edge in kiosk mode
Script part that launches Chrome or Edge in kiosk mode, on a Google login URL
Source: OALABS

The script also sets an ignore parameter for the F11 and Escape keys on the victim’s browser, preventing an easy escape from the kiosk mode.

Part that sets the browser to ignore presses of F11 and Esc keys
Ignoring presses of F11 and Esc keys
Source: OALABS

Kiosk mode is a special configuration used in web browsers or apps to run in full-screen mode without the standard user interface elements like toolbars, address bars, or navigation buttons. It’s designed to limit user interaction to specific functions, making it ideal for public kiosks, demonstration terminals, etc.

In this Amadey attack, though, kiosk mode is abused to restrict user actions and limit them to the login page, with the only apparent choice being to enter their account credentials.

For this attack, the kiosk mode will be opened to https://accounts.google.com/ServiceLogin?service=accountsettings&continue=https://myaccount.google.com/signinoptions/password, which corresponds to the change password URL for Google accounts.

As Google requires you to reenter your password before it can be changed, it provides an opportunity for the user to reauthenticate and potentially save their password in the browser when prompted.

Any credentials the victim enters on the page and then saves to the browser when prompted are stolen by StealC, a lightweight and versatile information stealer launched in early 2023.

Exiting the kiosk mode

Users who find themselves in the unfortunate situation of getting locked in kiosk mode, with Esc and F11 not doing anything, should keep their frustration in check and avoid entering any sensitive information on forms.

Instead, try other hotkey combos like  ‘Alt + F4’, ‘Ctrl + Shift + Esc’, ‘Ctrl + Alt +Delete’, and ‘Alt +Tab.’

Those may help bring the desktop on the foreground, cycle through open apps, and launch the Task Manager to terminate the browser (End Task).

Pressing ‘Win Key + R’ should open the Windows command prompt. Type ‘cmd’ and then kill Chrome with ‘taskkill /IM chrome.exe /F.’

If all else fails, you can always perform a hard reset by holding the Power button until the computer shuts down. This may result in losing unsaved work, but this scenario should still be better than having account credentials stolen.

When rebooting, press F8, select Safe Mode, and once you’re back on the OS, run a full antivirus scan to locate and remove the malware. Spontaneous kiosk mode browser launches are not normal and shouldn’t be ignored.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:56 pm, Jan. 24, 2025
Wetter-Symbol 8°C
L: 7° | H: 9°
overcast clouds
Luftfeuchtigkeit: 75 %
Druck: 1000 mb
Wind: 7 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:49 am
Sonnenuntergang: 4:35 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 9°°C 0 mm 0% 8 mph 75 % 1000 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 8°°C 1 mm 100% 7 mph 93 % 1010 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 8°°C 0 mm 0% 8 mph 75 % 1000 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 8°°C 0 mm 0% 5 mph 78 % 1000 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 7°°C 0 mm 0% 4 mph 85 % 999 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 1 mm 100% 7 mph 93 % 1001 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,790.46
2.16%
Ethereum(ETH)
€3,209.05
5.48%
XRP(XRP)
€2.99
2.43%
Fesseln(USDT)
€0.95
0.00%
Solana(SOL)
€248.95
6.46%
Dogecoin(DOGE)
€0.340607
3.91%
USDC(USDC)
€0.95
-0.01%
Shiba Inu(SHIB)
€0.000019
3.04%
Pepe(PEPE)
€0.000015
8.16%
Peanut das Eichhörnchen(PNUT)
€0.341906
3.03%
Nach oben scrollen