Beware of hackers
Published: 14th September 2022 | Source: Malwarebytes | Author: Mark Campbell

Steam users fall victim to a wave of browser-in-browser phishing attacks
Malwarebytes has issued a warning to Steam users about a new wave of phishing attacks that have seen the login credentials of stolen, allowing attackers to take control of a gamer's Steam account. Some of these attacks even accommodate for the protections provided by Steam's Guard mobile authentication system.
Attackers are using so-called browser-in-browser phishing techniques to harvest the Steam credentials of gamers, often using eSports teams and "votes" as a way to bring Steam users onto fake competition websites. These attacks often start when a compromised account sends a message to potential victims, asking them to join a team or league, or to enter a website and vote for their favourite eSports team/organisation.
Once on a fake eSports website, users are asked to log into their Steam account using a "browser-in-browser" technique that makes it appear like they are logging into their Steam account through an official Steam URL. Once Steam credentials are entered, the site will then ask for a Steam Guard authentication code. Once these details are gathered, attackers will log into their victim's Steam account and take control of it.

How to avoid these attacks
Malwarebytes has released the following tips that Steam users can utilise to protect themselves from these kinds of phishing attacks.
1. Block JavaScript on your browser (though this may break some websites)
2. Ignore all messages from Strangers on Steam that are related to the following topics.
- Joining an E-sports league
- Joining or helping out an E-sports team
- Voting for a team or individual
- The promise of cheap items or trades/discounts
- Free games, bonus promotional offers and items
- The “ I accidentally reported you ” scam
You can join the discussion on Steam users getting hit by browser-in-browser phishing scams on the OC3D Forums .