Skip to main content

Your Steam account could be in danger because of this new phishing technique

Hackers are once again targeting gamers, and this time around, you could lose your Steam account if you’re not careful.

Through the use of the Browser-in-the-Browser technique, hackers have been able to gain access to some high-profile Steam accounts valued as highly as $300,000. Here’s how the new hack works and how to make sure you’re staying safe.

New Steam hack that steals user credentials through a fake login website.
Group-IB

This new phishing attack is being carried out by hackers who contact Steam users in a well-concealed attempt to steal their accounts. Some phishing attempts are extremely easy to spot, but in this case, the whole thing seems to be legitimate, which only makes it easier for the hackers to gain control of Steam accounts.

Hackers send messages to potential victims via Steam, asking them to join a game of Counter-Strike, Dota 2, League of Legends, Rocket League, PUBG, or another popular esports title. Even if the user doesn’t accept, the hackers request that they vote for their team and provide a link to a website that looks to be an esports organization.

The website is quite well made — you’ve certainly seen similar pages before. It supports 27 languages and detects the correct language from your browser settings.

In order to join a team and play in a tournament or just a friendly match, the users are asked to log in through their Steam account, complete with the username, password, and even authenticator code if they have enabled two-factor authentication.

There’s one problem, though. The login page is not an actual browser window. Instead, it is a fake window that’s embedded within the current page. With this phishing kit, the fake window can even be dragged around, minimized, and maximized, closely resembling a regular pop-up.

If the user inputs their credentials and successfully logs in, they are redirected to an address that also appears legitimate. This is done in order to win the hackers some time while the login information is being sent to the attackers. The threat actors then quickly change the victim’s email and password, making it harder to recover the account.

How to protect yourself

A Steam Deck sitting on top of a PC.
Jacob Roach / Digital Trends

Many people have fallen victim to similar scams in the past, but now that they’re on the rise again and even harder to detect, it’s best to be careful and take your account security into your own hands.

As Group-IB reports, the technique relies on JavaScript (JS) in order to work. Blocking JS scripts would protect you well, but most of us don’t want to do that — many popular websites use JS, so that would affect your entire user experience.

Instead, be careful with links you receive from people you don’t know, and even people you do know. Discord and Steam accounts often get hacked, so receiving messages with links, even from friends, can be suspicious. Make sure you verify you’re actually talking to your friend before you ever follow any links sent to you, and if the person is a stranger, don’t bother — just block them.

Editors' Recommendations

Monica J. White
Monica is a UK-based freelance writer and self-proclaimed geek. A firm believer in the "PC building is just like expensive…
Hackers target your holiday shopping with new phishing scam
Woman using a laptop next to a latte.

It's easy to get fooled by this new and devious, holiday-themed phishing attack that offers free prizes. But the old caution that “if it sounds too good to be true, it probably is” continues to be proven correct in this case.

What makes this trick so effective is the elaborate methods used to conceal its nefarious purpose and to reassure you, the potential victim, that it’s perfectly OK to proceed. This phishing attack has actually been active since September and is ongoing, targeting holiday shoppers seeking special offers.

Read more
DuckDuckGo’s new browser could help keep Mac users safe on the web
DuckDuckGo is a privacy-first web browser.

DuckDuckGo is a relatively well-known alternative to the dominant Google search engine but it also makes a DuckDuckGo web browser for iPhone and Android phones that places your privacy and security first. Now the DuckDuckGo browser is available for your Mac computer as a public beta.

The top feature of DuckDuckGo's browser has always been a convenient Fire button in the upper right corner of every window that burns up browser history, cookies, web caches, and visited URLs keeping your privacy safe with a single click, even on a shared computer. Many more features than that have been added. Duck Player is included and prevents YouTube from using ad tracking, cookies, and recommended videos. DuckDuckGo email is similar to Apple's Hide My Email, providing an @duck.com address that redirects to your actual account and which can easily be switched off if overrun with spam.

Read more
Microsoft Edge now warns when your typos can lead to being phished
Microsoft Defender SmartScreen helps protect users against websites that engage in phishing and malware campaigns.

Microsoft has detailed its latest effort to protect against various types of fraud that can happen via a method as simple as spelling a website URL incorrectly.

The company has announced as of Monday that it is adding website typo protection to its Microsoft Defender SmartScreen service, to aid against web threats such as “typosquatters.” These types of cybercrime can include phishing, malware, and other scams.

Read more