New BitB Phishing Attack Targets Microsoft 365 Logins
ID: 88ea8f1c-c51a-5d0e-ba5c-9076713acb38
STIX ID: report--88ea8f1c-c51a-5d0e-ba5c-9076713acb38
Feed Name: GBHackers
Threat Score
A polished Browser-in-the-Browser (BitB) phishing campaign embeds draggable, spoofed OAuth login dialogs in webpages to harvest Microsoft 365 credentials and session data; it uses OS/browser fingerprinting and anti-analysis techniques to evade detection, and defenders are advised to adopt phishing-resistant authentication, conditional access, domain verification, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
