New Browser-in-the-Browser Phishing Attack to Steal Microsoft 365 Logins
ID: 46ec318e-b222-5e76-b371-137b875ffb1d
STIX ID: report--46ec318e-b222-5e76-b371-137b875ffb1d
Feed Name: cybersecurityNews.com
Threat Score
Unit 42 and Cyber Security News describe a sophisticated Browser‑in‑the‑Browser phishing campaign that embeds a draggable, device‑fingerprinted fake Microsoft OAuth login within malicious webpages to harvest credentials and OAuth consent grants; attackers use debugging blocks, keyword fragmentation, and bot redirection to evade detection, and stolen tokens can provide persistent access to Microsoft 365 environments even after password changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
