Steam Phishing Kit de077e20

Detects a Steam phishing kit that uses a fake Steam login window to steal user credentials and Counter Strike 2 Beta Access as bait.

References

IOK Rule (edit)

title: Steam Phishing Kit de077e20
description: |
  Detects a Steam phishing kit that uses a fake Steam login window 
  to steal user credentials and Counter Strike 2 Beta Access as bait.
references:
  - https://urlscan.io/result/de077e20-ab89-494b-af4c-df49f72d1e8b
  - https://urlscan.io/result/2fca4b90-38da-4880-9b09-14e3a94c68e6
  - https://urlscan.io/result/1daf0866-8168-4efe-9f37-067b89b886b4

detection:

  title:
    title: "Counter-Strike 2 | Limited Test"

  assets:
    requests|endswith|all:
      - '9d7ecea.js'
      - 'c9d2021.js'

  condition: title and assets

tags:
  - target.steam
  - threat_actor_country.russia