Hackers use Chrome Full Screen Mode to steal passwords

Recently, a new hacking method has emerged that is quite smart and annoying at the same time. Hackers are now taking advantage of kiosk mode In Chrome (Chrome Full Screen Mode) to force users to enter their Google password. As soon as the user enters the password, the data is immediately stolen and sent to the hacker. Reports from OALABS revealed that this attack is a combination of two very dangerous techniques.

What is chrome kiosk mode?

Before understanding more about this hacking mode, we must know kiosk mode in chrome. Kiosk mode is a display feature that makes the browser display the page in full screen or Chrome full screen mode, and is usually used on standalone service machines (such as in malls or public places). This mode will lock the screen, not allowing the user to move to another program or close the application easily. This is used by hackers to create a situation that seems to be the user is on the Google login page.

How does this hack work?

This attack works by taking advantage of Windows program which contains the fake Google login page in Chrome. After that, the program activates kiosk mode, makes the user unable to do anything but enter the password. Because the page looks exactly like the original login page, many users end up stuck.

After the password is entered, another program automatically steals the data and sends it to the hacker. The worst-case scenario that could happen is that the hacker directly changes your Google password, which causes you to be locked from your Gmail account, Google Drive, and other services connected to Google.

Why is this attack dangerous?

This attack is very dangerous because it uses a direct and deceptive approach. Even experienced users can be trapped because the appearance of the fake login page is identical to the original. In addition, because the kiosk mode locks the screen, users cannot close the browser or do other navigation easily. The combination of a clever attack and a trapped interface makes this attack difficult to avoid.

Who is vulnerable to this attack?

Hackers have targeted users Chrome on the operating system Windows, but this attack can also work in other browsers that have implementation kiosk mode similar. Since this attack does not require physical access to the victim’s device, anyone who downloads malicious programs from untrusted sources can become victims.

To enable this attack, the hacker only needs to run a malicious application that contains a fake login page in Chrome. As soon as the page opens and the kiosk mode is active, the victim is trapped and forced to enter their password.

Can this attack be prevented?

Clever users may be able to overcome this hack with a key combination Ctrl + Alt + Delete which will open Task Manager. From here, they can close the browser forcibly and end the trap. However, because it looks very much like a Google login page, many people reflexively enter a password without thinking. This is what makes this attack so effective.

How to protect yourself from this attack?

  1. Check the download source
    One of the best preventive measures is to be more careful in download#ATFP_CLOSE_TRANSLATE_SPAN# Applications or programs from the Internet. Make sure you only download from a trusted source and always recheck before installing a new program on your computer.
  2. Use a trusted antivirus
    Up-to-date antivirus can help detect malicious applications before they can run the action. If you accidentally get stuck in this situation, running a virus scanning immediately after getting out of the kiosk mode trap is very important.
  3. Avoid entering sensitive information on suspicious pages
    If suddenly you see the Google login page appear in full screen mode for no apparent reason, it is a danger sign. Always be suspicious of the login page that appears suddenly, especially if your browser is locked and cannot be navigated.
  4. Always enable two-step verification
    Two-step verification is an extra layer of security that is very helpful. By activating this feature, even if the hacker manages to get your password, they still can’t log into your account without an additional verification code sent to your phone.

How to deal with if you are trapped?

If you have already entered the password on this fake page, immediately do the following steps:

  1. Change your Google password immediately
    Open a Google account from another secure device and immediately change your password. Don’t wait long because the hacker may change your password and lock you out of your account.
  2. Check other accounts linked to Google
    Many third-party services use Google Login as an authentication method. Be sure to check out other accounts linked to your Google account and secure it if needed.
  3. Perform a virus scan
    After successfully getting out of the trap, be sure to run a virus scan on your computer. It is important to ensure that no other malicious programs remain in the system.

Google’s Steps to Solve This Problem

Google is always trying to update their security system to protect users from cyber threats. However, attacks like this show how smart and cunning hackers are in finding security loopholes. In recent years, Google has improved security features such as Introduction to Suspicious Login Activity and unknown device. However, the awareness and caution of the user remains the main key in fighting this threat.

Conclusion: Threats to watch out for in Full Screen Chrome Mode

This attack highlights how hackers always find new ways to exploit security vulnerabilities. Utilize kiosk mode In Chrome to create trap situations, hackers can steal Google login data easily. However, with caution and precautionary measures such as Check the download source, using antivirus, and does not immediately trust the suspicious login page, you can protect yourself from this threat.

Questions that arise:

  • Does this attack only apply in Chrome?
    Although this attack specifically utilizes the kiosk mode in Chrome, there is a possibility that a similar attack can occur in other browsers that have similar kiosk mode features.
  • How do I check if my computer is safe?
    Run a virus scan using a trusted antivirus software and make sure you update all the security software on your computer.
  • Are all full screen login pages dangerous?
    Not all full screen login pages are dangerous. However, if you find yourself stuck in a suspicious login page and can’t be navigated, get out and do a security check.

Cybersecurity is becoming increasingly important in this digital era. With attacks that are increasingly sophisticated and difficult to detect, we must always be aware of threats that may lurk at any time. Never be careless, and always make sure that you take appropriate protection measures.

Baca Juga

Back to top button

Adblock Detected

LidahTekno.com is supported by Google Adsense advertising to provide content for you.Please consider disabling AdBlocker or adding us to your whitelist so we can continue providing the best technology information and tips.Thank you for your support!