logo

Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins

ID: 6e03da4a-35cc-5a69-9dbe-56818667a82e

STIX ID: report--6e03da4a-35cc-5a69-9dbe-56818667a82e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes a surge in Facebook-focused phishing campaigns that use a sophisticated Browser-in-the-Browser (BitB) technique: attackers send fake law-firm emails with shortened links that redirect to hosted phishing pages (on platforms like Netlify and Vercel) presenting realistic in-browser Facebook login pop-ups and CAPTCHA prompts to harvest credentials and enable account takeover and identity fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.