Phishing Technique Bypasses MFA With Microsoft Edge WebView2 Applications

Share post:

Cybersecurity researcher mr.dox has developed a new phishing method that uses Microsoft Edge WebView2 applications to steal a user’s authentication cookies and log into stolen accounts, even if they are secured with MFA.

The new phishing technique, known as the WebView2-Cookie-Stealer consist of a WebView2 executable that opens the login of a legitimate website from inside the application.

Microsoft Edge WebView2 allows developers to embed a web browser directly into their native apps with Microsoft Edge. Microsoft Edge WebView2 allows apps to load any web page into a native application and make it look as if they have opened those applications in Microsoft Edge.

The new phishing POC opens the legitimate Microsoft login form using the embedded WebView2 control. It can be used to steal all cookies sent from the remote server after a user logs in, including authentication cookies.

For this purpose, the application creates a Chromium User Data folder at the first start and then uses this folder for each subsequent installation.

The attack also bypasses MFA, which are secured by OTPs or security keys. This is possible because the cookies are stolen after users have logged in and successfully solved the challenge of multifactor authentication.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways