CSS Bomb emails can steal webmail passwords
A malicious email can imitate a webmail login box and capture passwords as people type. The technique uses HTML and CSS instead of JavaScript or traditional malware.
- Report priority
- Medium
- Targets
- Yahoo Mail+3 more
How it works
- An attacker sends an email containing carefully arranged HTML and CSS.
- Differences between the email filter and browser display can let the message create a fake password field.
- Each typed character can trigger a hidden request to an attacker-controlled server.
What to do
When reading email, do not type credentials into a login box shown inside the message. Treat an unexpected login prompt inside an email as suspicious, regardless of which listed webmail service you use.
Avoid automatically loading remote images when your mail service offers that control. Open the provider's real website in a separate tab before entering a password, and follow its security notices for product-specific fixes.
Technical details
Affected software: Yahoo Mail, AOL Mail, Fastmail, ProtonMail
The attack abuses CSS selectors, pseudo-elements, and form-like email content to create a credential-capture interface. Each character can cause a background image request that reveals the typed value to an attacker-controlled server. Some reported flaws were patched, but no exact version details are supplied here.
References
- any.run · enterprise Cyber Security News
- bleepingcomputer.com · hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors BleepingComputer
- infosecurity-magazine.com · hugging-face-diffusers-trust Infosecurity Magazine
- openwall.com · 2 Openwall oss-security
- infosecurity-magazine.com · teams-phishing-abused-legit Infosecurity Magazine
- infosecurity-magazine.com · logokit-phishing-real-time Infosecurity Magazine
- neuracybintel.com · silent-takeovers-how-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys-on-windows NeuraCybIntel
- openwall.com · 1 Openwall oss-security