logo

Kiosk Mode Attack: New Cyber Threat Steals Browser Credentials

ID: 0a320805-5ee3-54e4-95ae-def0c5f168b5

STIX ID: report--0a320805-5ee3-54e4-95ae-def0c5f168b5

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-09-17

Date Updated: 2026-04-22

Author: do son

...
...

OALabs researchers identified an active campaign where Amadey installs StealC and an AutoIt-based “Credential Flusher” that forces browsers into kiosk mode on legitimate sites (commonly Google login), coercing victims to re-enter credentials which are then captured by the stealer; the technique was first observed in late August and is reportedly gaining popularity among cybercriminals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.