A clever, new phishing technique uses Microsoft Edge WebView2 applications to steal victim’s authentication cookies, allowing threat actors to bypass multi-factor authentication when logging into stolen accounts.
With the large number of data breaches, remote access trojan attacks, and phishing campaigns, stolen login credentials have become abundant.
However, the increasing adoption of multi-factor authentication (MFA) has made it difficult to use these stolen credentials unless the threat actor also has access to the target’s one-time MFA passcodes or security keys.
This has led to threat actors and researchers coming up with new ways of bypassing MFA, including zero-day website vulnerabilities, reverse proxies, and clever techniques, such as the Browser in the Browser attack and utilizing VNC to display remote browsers locally.
This week, cybersecurity researcher mr.d0x has created a new phishing method that uses Microsoft Edge WebView2 applications to easily steal a user’s authentication cookies and log into stolen accounts, even if they are secured with MFA.
Microsoft Edge WebView2 to the rescue
This new social engineering attack is called WebView2-Cookie-Stealer and consists of a WebView2 executable that, when launched, opens up a legitimate website’s login form inside the application.
Microsoft Edge WebView2 allows you to embed a web browser, with full support for HTML, CSS, and JavaScript, directly in your native apps using Microsoft Edge (Chromium) as the rendering engine.
Using this technology, apps can load any website into a native application and have it appear as it would if you opened it in Microsoft Edge.
However, WebView2 also allows a developer to directly access cookies and inject JavaScript into the webpage that is loaded by an application, making it an excellent tool to log keystrokes and steal authentication cookies and then send them to a remote server.
In the new attack by mr.d0x, the proof-of-concept executable will open the legitimate Microsoft login form using the embedded WebView2 control.
As you can see below, the login form renders exactly as it would when using a regular browser and does not contain any suspicious elements like typos, strange domain names, etc.
WebView2 phishing attack opening the Microsoft login form Source: BleepingComputer
As a WebView2 application can inject JavaScript into the page, anything the user types is automatically sent back to the attacker’s web server.
However, the true power of this type of application is the ability to steal any cookies sent by the remote server after a user logs in, including authentication cookies.
To do this, mr.d0x told BleepingComputer that the application creates a Chromium User Data folder the first time it runs and then uses that folder for each subsequent install.
The malicious application then uses the built-in WebView2 ‘ICoreWebView2CookieManager’ interface to export the site’s cookies on successful authentication and sends them back to the attacker-controlled server, as shown below.
The malicious WebView2 app sending back the stolen cookies Source: BleepingComputer
Once the attacker decodes the base64-encoded cookies, they will have full access to the authentication cookies for the site and can use them to log in to a user’s account.
Decoded cookies stolen by the WebView2 application Source: BleepingComputer
The researcher also found that it was possible to use the WebView2 app to steal cookies for an existing Chrome user profile by copying their existing Chromium profile.
“WebView2 can be used to steal all available cookies for the current user. This was successfully tested on Chrome,” explains a report on this technique by mr.d0x.
“WebView2 allows you to launch with an existing User Data Folder (UDF) rather than creating a new one. The UDF contains all passwords, sessions, bookmarks etc. Chrome’s UDF is located at C:UsersAppDataLocalGoogleChromeUser Data.”
“We can simply tell WebView2 to start the instance using this profile and upon launch extract all cookies and transfer them to the attacker’s server.”
When asked how an attacker could use these cookies, mr.d0x told BleepingComputer that they could go to the login form for an account they stole and import the cookies using a Chrome extension like ‘EditThisCookie.’ Once the cookies are imported, they simply refresh the page to automatically be authenticated on the site.
What is more concerning, though, is that this attack also bypasses MFA secured by OTPs or security keys, as the cookies are stolen after the user logged in and successfully solved their multi-factor authentication challenge.
“So lets say the attacker sets up Github.com/login in their webview2 app, and the user logs in, then cookies can be extracted and exfil’d to the attacker’s server.”
“Yubikeys can’t save you because you’re authenticating to the REAL website not a phishing website.”
mr.d0x
Furthermore, these cookies will be valid until the session expires or there is some other post-authentication check that detects unusual behavior.
“So unless they have some additional checks POST-AUTHENTICATION then that won’t be detected, and of course this is not so easy to implement,” mr.d0x told BleepingComputer.
Attack requires social engineering
However, as mr.d0x admits and Microsoft pointed out in their response to our questions, this attack is a social engineering attack and requires a user to run a malicious executable.
“This social engineering technique requires an attacker to convince a user to download and run a malicious application,” Microsoft told BleepingComputer in a statement regarding this new technique.
“We recommend users practice safe computing habits, avoid running or installing applications from unknown or untrusted sources, and keep Microsoft Defender (or other anti-malware software) running and up-to-date.”
Therefore, getting someone to run an application in the first place may take additional work.
With that said, history has shown us that many people “just run things” without thinking about the ramifications, whether that be email attachments, random downloads off the Internet, cracks and warez, and game cheats.
All of these methods are proven to work with fairly little effort, leading to the installation of ransomware, remote access trojans, password stealing trojans, and more.
Therefore, the researcher’s WebView2 attack is feasible, especially if created to look like a legitimate application installer that requires you to log in first. For example, a fake Microsoft Office installer, game, or Zoom client.
While this attack has not been seen used in real-world attacks, the researcher’s techniques have been quickly used in attacks in the past, so this is something that security admins and professionals need to keep an eye on.
As for how to protect yourself from these attacks, all the regular cybersecurity advice remains the same.
Do not open unknown attachments, especially if they are executables, scan files you download from the Internet and do not enter your credentials into an application unless you are 100% sure the program is legitimate.
Authentication
cookie
Multi-Factor Authentication
Phishing
WebView2
News Related
-
Regina Police is asking for the public’s help in locating a 2-year-old baby and 36-year-old mother who is under investigation for abducting the child. Two year-old Holdan Keewatin was last seen wearing a black and white horizontal striped outfit. Regina Police According to a news release, officers were dispatched to ...
See Details:
Regina Police issue amber alert to find mom who allegedly abducted her child
-
Mexican President Andres Manuel Lopez Obrador visited a disaster-hit coal mining region on Sunday to see first-hand a major operation to try to rescue 10 trapped workers. Relatives of the missing were becoming increasingly desperate four days after the mine flooded in the northern state of Coahuila, fearing time is ...
See Details:
Time is running out for 10 trapped miners, Mexican president visits
-
-
-
Little is known about the dietary requirements of coral larvae but new Australian research has revealed feeding them can improve their chances of survival. Key points: New research has found feeding coral larvae boosts their energy levels at a critical stage of development It is not yet known exactly how the ...
See Details:
Feeding coral larvae helps them grow and survive, new research finds
-
Dominic Perrottet denies NSW minister David Elliott (right) was promised a post-politics role. Photo: AAP Live NSW Premier Dominic Perrottet admits he and David Elliott talked about potential jobs the Transport Minister could do after retiring from politics, but denies any promises were made. “The allegations in relation to the ...
See Details:
Dominic Perrottet denies promising trade job to Elliott
-
The estimated $740bn package heads next to the House, where legislators are poised to deliver on Biden’s priorities after it passed through the Senate [File: J. Scott Applewhite/AP] Democrats pushed their election-year economic package to Senate passage, a hard-fought compromise less ambitious than President Joe Biden’s original vision — but ...
See Details:
Senate Democrats pass budget package, a major victory for Biden
-
Report: Dozens got sick after visiting Kansas splash park A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, last summer GODDARD, Kan. — A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, ...
See Details:
Report: Dozens got sick after visiting Kansas splash park
-
-
-
Report: Dozens got sick after visiting Kansas splash park A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, last summer GODDARD, Kan. — A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, ...
See Details:
White Sox Pound Out 15 Hits, Beats Rangers 8-2 for Series Split
-
Report: Dozens got sick after visiting Kansas splash park A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, last summer GODDARD, Kan. — A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, ...
See Details:
Icon Tony Bennett turns 96 during a busy NYC summer of celebrity sightings
-
Report: Dozens got sick after visiting Kansas splash park A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, last summer GODDARD, Kan. — A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, ...
See Details:
Family Guy Was Quick To Change A Prominent Detail About Lois
-
Report: Dozens got sick after visiting Kansas splash park A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, last summer GODDARD, Kan. — A new federal study said dozens of people got sick after visiting a splash park near Wichita, Kansas, ...
See Details:
Kardashian News Drop: a Baby and a Breakup
OTHER NEWS
The new plan to encourage Americans to buy more electric vehicles built in North America, instead of just the United States, has cleared its tallest hurdle. After a marathon voting ...
Read more »
Getty Images Longtime CBS golf broadcaster Nick Faldo is taking off his headset after 16 years. Faldo bid farewell Sunday during the final round of the 2022 Wyndham Championship at ...
Read more »
An MTA staffing shortage has forced trains to run slower and caused a number of cancellations. Getty Images The MTA is still struggling to staff trains and buses a year ...
Read more »
Civil rights activist Al Sharpton is in a rental dispute with the owner of the building his group, the National Action Network, is headquartered in. Robert Miller Civil rights activist ...
Read more »
A solemn scene unfolded as a ceremony took place at Chicago Police Headquarters to enshrine French's Chicago Police Star
Read more »
The estimated $740 billion package — passed Sunday by the Senate and heading to the House — is full of party priorities
Read more »
Nathanial Harland was four years old when his daycare teachers noticed the usually playful boy was lethargic and alone in a corner. That day a doctor listened to the child’s ...
Read more »
Authorities suspect a serial killer is targeting Muslims in Albuquerque, New Mexico. ZUMAPRESS.com Authorities are investigating the possibility that a serial killer has been hunting Muslim people in Albuquerque, New ...
Read more »
MODEL Stella Maxwell and pals show they are a four to be reckoned with during a photoshoot in Ibiza. The Victoria’s Secret Angel, 32, far right, kept her modesty as ...
Read more »
LOVE Island fans have slammed Laura Whitmore for an “intrusive” comment she made to Tasha Ghouri and Andrew Le Page during the reunion episode. The 37-year-old presenter was talking to ...
Read more »
LIVE – Updated at 23:15 Follow all the latest developments. 23:15 Stephanie Convery Australian education ministers to address nationwide teacher shortages Australia’s education ministers will attempt to address the ...
Read more »
PROPERTY site Zoopla has revealed Bradford is the most popular place to buy a home in Britain. It said that since 2017 demand had risen by 98 per cent for ...
Read more »
LOVE Island fans were shocked to see Summer Botwe and Coco Lodge's furious bust-up teased in shock reunion scenes – and wanted to see more. The pair came face to ...
Read more »
PRISONERS are being given budgies as a reward for good behaviour. Bosses hope the chatty birds will help keep lags chirpy. Jail bosses are giving lags budgies, tropical fish and ...
Read more »
Renowned Jiu-jitsu fighter Leandro Lo was killed after an alleged confrontation with a police officer in Sao Paulo, Brazil. Francois Nel/Getty Images Legendary Jiu-jitsu fighter Leandro Lo was fatally shot ...
Read more »
The upgrades to the Jets’ passing defense are obvious. They signed cornerback D.J. Reed and safety Jordan Whitehead in free agency, drafted corner Sauce Gardner No. 4 overall, selected pass ...
Read more »
Khloe has a confessional with Kim Kardashian on Keeping Up With The Kardashians. Love frequently can be found in the air surrounding the Kardashian family, and those relationships often fuel ...
Read more »
The Lone Star State is home to some wonderful bookstores
Read more »
LA native and actor best known for his role on "Magnum, P.I.", Roger Mosley has died Sunday at the age of 83.
Read more »
Check here for real-time updates of the U.S. stock market. Stock futures were flat in overnight trading Sunday, following the S&P 500’s third straight weekly gain, as investors shifted focus to ...
Read more »
WASHINGTON — Brittney Sykes scored 21 points, including a driving layup in the closing seconds, and the Los Angeles Sparks kept their slim playoff hopes alive Sunday with a 79-76 win ...
Read more »
jQuery(function(){ if (typeof jwplayer_load == typeof indefined) { var jwplayer_load = 1; jQuery(window).load(function(){ jQuery(".sc_video_shortcode_jwplayer").each(function(){ var _this = $(this); jQuery.get(jQuery(this).attr("url"), function(data, status){ if (typeof data.split("\n") !== typeof undefined) { var src ...
Read more »
Neighbours have expressed their horror after a ferocious 'pitbull' attacked a teenage girl and a takeaway delivery driver. The dog was then shot dead by police marksmen, with armed officers ...
Read more »
A teenager who was stabbed to death begged bystanders for help before collapsing outside a pizza restaurant. Police were called to reports of an attack in East London and on ...
Read more »
All the predraft talk about whether his “brand” was more important than it should be for Kayvon Thibodeaux is gone with the wind. Which happens to be a good way ...
Read more »
Davide Sanclimenti and Ekin-Su Cülcüloğlu have poked fun at their old arguments in a new video (Picture: Love Island/ Youtube) Love Island’s Ekin-Su Cülcüloğlu and Davide Sanclimenti are as loved-up ...
Read more »
What comes to mind when you think of blindness? Is it a person donning dark sunglasses, possibly with a cane, or a guide dog? There are certainly people with vision loss ...
Read more »
Matthew Piscopo and Shamus Touhy are currently on the run after escaping a youth prison. (Supplied) Two young men are on the run after breaking out of the Malmsbury Youth Justice ...
Read more »
كشف استطلاع جديد أن أكثر من ربع أصحاب الرهن العقاري في أستراليا يعانون بعد ارتفاع اقساط السداد لقروضهم العقارية بأكثر من ستة في المائة منذ بداية العام.جاء ذلك في نتائج ...
Read more »
The Manhattan eatery owner whose outside dining shed has been used as a sex den says the situation makes her stomach churn — but she’s virtually helpless to stop the ...
Read more »
Israel and Islamic Jihad militants on Sunday agreed an Egyptian-brokered truce hoped to end three days of intense conflict that has left at least 43 Palestinians dead, including 15 children.The ...
Read more »
jQuery(function(){ if (typeof jwplayer_load == typeof indefined) { var jwplayer_load = 1; jQuery(window).load(function(){ jQuery(".sc_video_shortcode_jwplayer").each(function(){ var _this = $(this); jQuery.get(jQuery(this).attr("url"), function(data, status){ if (typeof data.split("\n") !== typeof undefined) { var src ...
Read more »
jQuery(function(){ if (typeof jwplayer_load == typeof indefined) { var jwplayer_load = 1; jQuery(window).load(function(){ jQuery(".sc_video_shortcode_jwplayer").each(function(){ var _this = $(this); jQuery.get(jQuery(this).attr("url"), function(data, status){ if (typeof data.split("\n") !== typeof undefined) { var src ...
Read more »
Frenkie de Jong lit up Barcelona ‘s final friendly of pre-season to further show Manchester United that he is happy to stay at the Nou Camp. Barca hosted Mexican side ...
Read more »
Heatwaves sweeping Europe this summer have brought more than just record high temperatures; the drought-stricken waters of Italy's River Po are so low they have revealed a previously submerged World War ...
Read more »
Pauline Follett has been struggling to get on the National Disability Insurance Scheme (NDIS) for three years and is “frustrated” with the health system. The 54-year-old has been living with ...
Read more »
Queenslanders spent $2.8 billion on pokies in pubs and clubs in the 12 months to June. (ABC Gold Coast: Kimberley Bernard) Poker machines are “a dangerous product” like heroin and guns, according to ...
Read more »
LONDON — A museum in southeast London agreed Sunday to return a collection of Benin Bronzes looted in the late 19th century from what is now Nigeria as cultural institutions throughout ...
Read more »
Sky beat Sun 94-91, set franchise’s win record originally appeared on NBC Sports Chicago Candace Parker scored 18 points, grabbed 12 rebounds and tipped a pass to Emma Meesseman for ...
Read more »
LONDON – London’s Horniman Museum said on Sunday it would return 72 artefacts, including 12 brass plaques known as Benin Bronzes, looted from Benin City by British soldiers in 1897 ...
Read more »