Steam Phishing: popular as ever
ID: 953b1c7e-6397-5eb5-b979-3809aa35bcde
STIX ID: report--953b1c7e-6397-5eb5-b979-3809aa35bcde
Feed Name: Blaze's Security Blog
A phishing campaign targets Steam users via friend messages linking to lookalike domains of steamcommunity.com that redirect to a fake “Summer Gift Marathon” login page to steal credentials and potentially inventory items. The report enumerates many typosquatted domains used in the campaign and advises defenses such as only logging in at https://steamcommunity.com/, bookmarking the legitimate site, treating unsolicited links from friends as suspicious, and checking URLs with services like URLscan.io and VirusTotal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
