Skip to main content

New phishing method looks just like the real thing, but it steals your passwords

Thanks to a new phishing method, hackers could steal all sorts of personal information by simply mimicking real login forms in Application Mode. This is a feature that’s available in all Chromium-based browsers, which includes Google Chrome, Microsoft Edge, and Brave.

Using Application Mode allows threat actors to spread highly believable-looking local login forms that look like desktop applications. In reality, all inputs are sent to a malicious attacker.

Related Videos
Two Microsoft sign in prompts -- one fake, one real, side by side.
mr.d0x

In Google Chrome, Application Mode lets web devs create apps that resemble native applications. A few things happen when you launch Application Mode. For starters, the toolbars and the address bar both disappear. The website is launched in a separate window, and on your taskbar, you’ll see the website’s favicon (the icon you normally see next to the website’s name in your browser tab) instead of the Chrome logo.

With all of these things out of the equation, it’s fairly easy to create a clone of a familiar login form and try to trick users into typing their login credentials. Many users are less wary of desktop apps than websites, because once installed, they are assumed to be safe; on the other hand, there’s always some degree of hesitation when visiting a strange website. Removing the URL largely deals with the easiest way to spot a scam from the real thing.

This hack could potentially be very dangerous simply because of how easy it might be to get fooled by it. On the other hand, actually pulling it off requires the victim to have Chromium app mode enabled and launched locally on their device. This means that the hacker would first have to gain some sort of control over the computer before following up with this phishing method, be it through malware or through guiding the user to enable it and run a Windows shortcut with the phishing URL.

Windows 10 and 11 both come with Microsoft Edge pre-installed. This makes it easier to distribute Windows shortcut files that launch Microsoft Edge, and from there, it’s smooth sailing for the hacker if the victim falls for the fake form.

Google Chrome opened on a laptop.
Caio/Pexels

This phishing method was first described by mr.d0x and later reported on by Bleeping Computer. While it could be dangerous if users were to fall for it, the prerequisite of first obtaining some sort of access to the victim’s computer should largely keep you safe.

As always, remember not to visit websites that you don’t fully trust, load up some trustworthy antivirus software for good measure, and do not enable Application Mode in your browser unless you have a very good reason to do so.

Editors' Recommendations

The most common Chromebook problems and how to fix them
A person working on a Toshiba Chromebook.

Chromebooks are great alternatives to MacBooks and Windows 10 laptops, but they aren’t perfect. Any laptop computer is bound to have issues, and some of the most common problems faced by Chromebook users can feel difficult or even impossible to solve on their own. 

From issues with updates to internet connectivity, troubleshooting common Chromebook problems doesn’t have to ruin your day. Read on to discover easy fixes for the most frequent issues Chromebook users face. 
The Diagnostics app

Read more
Ranking all 12 versions of Windows, from worst to best
Windows 7 desktop.

You can tell a person's age by which version of Windows is their favorite. I have fond memories of XP and Windows 98 SE, so you can take a guess at mine, but I have colleagues who are much more enamored with Windows 7, or Windows 95. We all have something disparaging to say about Windows 8 though, and the less said about Windows Vista the better.

Ranking the different versions of Windows is about more than what era of computing you grew up in, though. There are some very serious duds in Microsoft's back catalog, just as there are a few wins too. But whether you can look back on some of Microsoft's disastrous releases with rose-tinted glasses, or have some genuine love for Microsoft's missteps, here's every version of Windows ranked from best to worst.
12. Windows ME

Read more
If you use this free password manager, your passwords might be at risk
Office computer with login asking for password and username.

Researchers have just found a flaw within Bitwarden, a popular password manager. If exploited, the bug could give hackers access to login credentials, compromising various accounts.

The flaw within Bitwarden was spotted by Flashpoint, a security analysis firm. While the issue hasn't received much -- or any -- coverage in the past, it appears that Bitwarden was aware of it all along. Here's how it works.

Read more