How The Attack Works ?
A user navigates to your normal looking site.
A malicious code detect when the page has lost its focus and hasn’t been interacted with for a while.
Replace the favicon with the Gmail favicon, the title with “Gmail: Email from Google”, and the page with a Gmail login...