logo

Malware locks browser in kiosk mode to steal Google credentials

ID: 546fcac8-3291-54cf-b54e-e57b3be28d73

STIX ID: report--546fcac8-3291-54cf-b54e-e57b3be28d73

Feed Name: Bleeping Computer

Threat Score
68/100

Date Published: 2024-09-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers uncovered a campaign where the Amadey loader deploys an AutoIt script that launches victim browsers in kiosk mode on Google’s reauthentication page while disabling Escape/F11, coercing users to enter and save Google credentials; saved credentials are then stolen by the StealC information stealer. The report details the attack timeline (active since at least Aug 22, 2024), script snippets, user mitigation steps to exit kiosk mode, and guidance to run antivirus scans after rebooting in safe mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.