logo

New BitB Phishing Attack Targets Microsoft 365 Logins

ID: 88ea8f1c-c51a-5d0e-ba5c-9076713acb38

STIX ID: report--88ea8f1c-c51a-5d0e-ba5c-9076713acb38

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Mayura Kathir

...
...

A polished Browser-in-the-Browser (BitB) phishing campaign embeds draggable, spoofed OAuth login dialogs in webpages to harvest Microsoft 365 credentials and session data; it uses OS/browser fingerprinting and anti-analysis techniques to evade detection, and defenders are advised to adopt phishing-resistant authentication, conditional access, domain verification, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.