logo

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials

ID: be085051-9789-58ac-8dd2-092c304994db

STIX ID: report--be085051-9789-58ac-8dd2-092c304994db

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Sinisa Markovic

...
...

Palo Alto Networks Unit 42 warns of an active Browser-in-the-Browser (BitB) phishing campaign targeting Microsoft 365 users: malicious webpages open fake, draggable browser-like OAuth login popups that mirror the victim's OS and browser to collect credentials. The campaign employs evasion techniques—sandboxed iframes for credential harvesting, console function overrides, fragmented text to evade keyword checks, and redirecting bots to legitimate Microsoft pages—and Unit 42 published domains associated with the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.