DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
VGSources
Blog

How Browser-in-the-Browser Attacks Stole Steam Accounts: The 2022 Scam Explained

A 2022 phishing campaign used fake Steam popups inside tournament and voting websites. Here is how BitB works, how to spot it, and what to do after entering credentials.
Length8 min Posted Quest giverVGSources Team
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Browser-in-the-Browser (BitB) phishing can make a fake Steam login window appear inside an ordinary webpage. The attacker controls the apparent popup, including its browser controls, padlock, and displayed Steam URL. If you enter your Steam password—and especially a Steam Guard code—into that imitation, the information can be relayed to the attacker.

The Steam campaign described here was reported by Group-IB in September 2022, not as a new August 2026 incident. Its lures included esports tournaments, team votes, and discounted event tickets.

As an Amazon Associate I earn from qualifying purchases.

The short version

  • A message on Steam, Discord, or another gaming community may invite you to join a tournament, vote for a team, or buy esports tickets.
  • The link opens a convincing gaming website containing a simulated Steam sign-in window.
  • The fake window may display a legitimate-looking Steam URL, HTTPS padlock, Steam branding, browser controls, and even a Steam Guard prompt.
  • Those elements can all be webpage content. They do not prove that the window is genuine.
  • The safest response is to close the link and open Steam independently through the official client, a known bookmark, or a manually entered official domain.

Steam’s official guidance says to enter account information only on official Steam domains, including steampowered.com, store.steampowered.com, steamcommunity.com, and help.steampowered.com.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened in the 2022 Steam campaign?

According to Group-IB’s account, attackers targeted Steam users with valuable gaming accounts and inventories. The observed chain was straightforward:

#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. A victim received a message from a Steam contact, Discord user, or gaming community.
  2. The message promoted a League of Legends, Counter-Strike, Dota, or PUBG tournament, team invitation, team vote, or discounted esports ticket.
  3. The supplied link opened a fake tournament or esports site.
  4. The site displayed a simulated Steam login popup.
  5. The victim entered a Steam username and password.
  6. The page requested a Steam Guard or other two-factor authentication code.
  7. The attacker received the submitted details and could attempt to use them during the code’s short validity period.
  8. The victim could then be redirected to a legitimate-looking website, making the login appear to have worked normally.

The campaign was reported by BleepingComputer on September 12, 2022. It should not be confused with separate, later Browser-in-the-Browser reporting, including coverage indexed by BleepingComputer about attacks targeting Counter-Strike 2 players in March 2025.

What is Browser-in-the-Browser?

Browser-in-the-Browser is a phishing presentation technique, not necessarily a browser vulnerability. JavaScript, HTML, and CSS inside an attacker-controlled page draw a window that resembles a separate browser window or OAuth login dialog.

The fake window is designed to exploit familiar behavior. Users expect a tournament site to open a Steam sign-in popup, so a convincing imitation can feel trustworthy even though it never left the original webpage. The attacker can draw a fake title bar, browser buttons, address field, HTTPS indicator, and login form as ordinary page elements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The technique was publicly described by security researcher mr.d0x in March 2022, with examples imitating login windows for Steam, Google, Microsoft, and other services. The available evidence describes abuse of authentication expectations and user trust—not a confirmed vulnerability in Valve’s servers.

Why the fake Steam popup looks real

The observed kit used several details to reduce suspicion:

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Familiar branding: Steam logos, colors, and a recognizable sign-in layout.
  • Fake browser chrome: A title bar, controls, and address field make the form look like a separate browser window.
  • A fake padlock: The lock icon may simply be an image or HTML element inside the imitation.
  • A convincing URL: The attacker can print steampowered.com or another legitimate-looking address inside the fake address field.
  • Interactive behavior: The imitation may be draggable, minimizable, resizable, or closable.
  • Localization: BleepingComputer reported that the observed kit supported automatic language selection across 27 languages.
  • A final redirect: Sending the victim to a real website after collection can conceal the theft.

The displayed URL inside the popup is not the browser’s real address bar. It is content rendered by the page and therefore controlled by the attacker.

How to recognize a fake Steam login

1. Do not authenticate from an unsolicited link

This is the strongest defense. Open Steam directly through the official desktop or mobile app, a known bookmark, or by manually entering the official domain. Do not use a tournament or voting link delivered unexpectedly in a chat.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Steam specifically warns that requests to vote for or support a friend’s team or account in a tournament or contest are likely phishing attempts—even when the message appears to come from a trusted friend whose account may have been compromised. See Steam’s official tournament and voting warning.

2. Inspect the real browser address bar

Look at the browser’s actual address bar at the top of the browser window, not the address field drawn inside the apparent popup. A legitimate-looking URL inside the simulated window proves nothing.

A matching official domain in the real address bar is an important check, but it is not an absolute guarantee: a legitimate site could be compromised, or a page could redirect you. Independent navigation remains safer than trusting the original link.

Rank #3
Sale
Yubico - YubiKey 5 NFC Bundle (USB-A + USB-C) - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB or NFC, FIDO Certified - Protect Your Online Accounts
  • Works with 1000+ Accounts: It’s compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more.
  • Fast & Convenient Login: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required.
  • Most Secure Passkey: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • Built to Last: Made from tough, waterproof, and crush-resistant materials. Made in Sweden with the highest security standards.
  • Yubico Authenticator App: Compatible with the safest authenticator app experience across mobile and desktop.

3. Try moving the window beyond the page

On a desktop, a genuine separate browser window can normally be moved independently of the original browser. A simulated BitB window is confined to the webpage and cannot truly cross the browser’s boundaries; it may slide underneath or remain trapped in the viewport.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is only a secondary clue. Attackers can change the imitation’s behavior, and the test is not universal on phones or tablets. Browser fullscreen modes, operating-system window handling, taskbars, and window grouping also vary.

4. Treat taskbar and minimize behavior cautiously

A real operating-system window may have its own taskbar entry and may minimize or resize independently. Those clues are platform-dependent. Windows taskbar grouping settings and differences between Windows 10 and Windows 11 mean that the absence of a separate taskbar entry is not conclusive.

5. Never trust the padlock alone

HTTPS indicates an encrypted connection to the site currently loaded. It does not certify that the site is legitimate. In a BitB attack, the apparent padlock may be entirely fake and drawn inside the webpage.

Does Steam Guard stop Browser-in-the-Browser phishing?

Steam Guard remains valuable, but it cannot protect a code that the user hands to the phisher. It adds an authorization requirement when a login comes from an unrecognized computer, helping prevent password-only account theft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The problem is the authentication boundary. If a victim enters a valid Steam Guard code into a counterfeit form, the attacker may relay it to Steam during its short validity period. The attacker is not necessarily breaking Steam Guard; they are tricking the user into supplying the second factor during a live login attempt.

Therefore, a code request on an untrusted tournament or voting page is itself a warning sign. Keep the approval and code entry within the genuine Steam interface. Multi-factor authentication still blocks many password-only attacks and should be enabled.

Real Steam OAuth is different from a fake login form

Not every tournament website that connects to Steam is fraudulent. A legitimate third-party service may use Steam’s OAuth or OpenID flow so that Steam handles authentication and the third party does not receive your Steam password.

That does not make every popup safe. Verify the real browser domain and read the authorization request. Be especially cautious if a site asks you to type your Steam password directly into a form hosted on the tournament site rather than handing authentication to Steam’s genuine domain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What attackers can do with a stolen account

After obtaining credentials and authentication details, attackers may change the Steam password or associated email address, lock the owner out, and use the account for financial or social abuse. Possible consequences include:

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Unauthorized trades or transfers of valuable inventory items.
  • Use of Steam Wallet funds or unauthorized purchases.
  • Changes to email, phone, or authenticator settings.
  • Messages sent to friends containing the same phishing lure.
  • Attempts to access other services if the Steam password was reused.

Steam accounts can be attractive targets because some contain valuable inventories, tradable items, wallet balances, or access to established gaming communities. BleepingComputer’s 2022 coverage cited claims of prominent accounts valued at $100,000 to $300,000; those were claims about exceptional accounts, not a normal Steam-account value or current market average.

What to do if you interacted with the scam

If you only clicked the link

  1. Close the page and do not return to it.
  2. Open Steam independently and check for unusual account activity.
  3. If you did not enter credentials, a password change may not be necessary solely because of the click, but change it if anything looks suspicious.

If you entered your Steam password but no Steam Guard code

  1. From a trusted device, change the Steam password through the genuine Steam site or client.
  2. Secure the associated email account, especially if its password was reused or exposed.
  3. Change that reused password anywhere else.
  4. Review unfamiliar sessions, devices, account details, trades, inventory transfers, and wallet activity.
  5. Enable or re-enable Steam Guard.
  6. Warn friends that recent messages from the account may be malicious.

Steam’s account-security guidance and stolen-account workflow are the correct recovery routes.

If you entered a Steam Guard code

Assume the account may be compromised immediately:

  1. Secure the associated email account first.
  2. Try changing the Steam password through the genuine Steam interface.
  3. If access is lost, use Steam Support’s Help, I can’t sign in or stolen-account route.
  4. Check for password, email, phone, authenticator, trade, inventory, and wallet changes.
  5. Contact your payment provider about unauthorized purchases.
  6. Report the phishing page and the accounts distributing it.

Do not pay an alleged recovery expert who contacts you through Discord, Steam chat, or social media. Steam warns that genuine support representatives do not use unofficial chat channels to request account information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you downloaded or ran a file

The BitB campaign described above is primarily a credential-phishing scenario. Downloading an “anti-cheat,” tournament tool, browser extension, or executable creates a separate malware risk.

  1. Disconnect the device from sensitive accounts while investigating.
  2. Run an up-to-date security scan.
  3. Remove recently installed unknown applications and browser extensions.
  4. Change passwords from a clean, trusted device.
  5. Assume browser-saved passwords may be exposed if an infostealer ran.
  6. Check email forwarding rules, recovery addresses, and unfamiliar sessions.

Steam advises downloading software only from official sources. These steps do not mean the 2022 BitB kit itself installed malware; they apply when a victim separately downloaded or executed software.

Practical defenses

  • Enable Steam Guard: It is an important baseline defense even though it cannot stop a phished code.
  • Use a unique Steam password: This limits damage if another service is breached.
  • Protect the email account: Email access can allow password resets and account takeover.
  • Use a password manager if appropriate: Many managers can distinguish domains and may not autofill on an impostor site. They cannot stop manually typed credentials or a phished authentication code.
  • Keep software updated: Browser warnings and endpoint security can help with some malicious sites or malware, but they are not a substitute for link avoidance.
  • Be skeptical of urgency: Tournament deadlines, voting windows, prizes, and requests from “friends” are common social-engineering pressure points.

Aggressive JavaScript blocking may prevent some fake windows from rendering, but it can also break ordinary websites and is not a practical sole defense for most users.

Bottom line

The Browser-in-the-Browser Steam campaign was a 2022 phishing operation, not evidence that Steam Guard or Steam’s servers were fundamentally broken. Its strength came from making a webpage look like a trusted authentication window. Ignore the popup’s branding, padlock, and printed URL; avoid unsolicited login links, open Steam independently, and treat any code entered into a fake form as an immediate account-security incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For official guidance, use Steam’s account-security FAQ and its stolen-account recovery page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More quests from Patch Notes

  1. How to Set Up a RedM (RDR2) Server in 2026: License Key, txAdmin and server.cfg, Step by StepBlog11min
  2. Best RedM (RDR2) Server Hosting in 2026: Comparing Four Hosts on Slots, Memory and PriceBlog10min
  3. How to Host a Mindustry Server in 2026: server-release.jar, Port 6567 and the Commands That MatterBlog7min
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.