Update: Mauro Soria pointed out that this attack vector can be easily adapted for phishing scenarios: