logo

Facebook login thieves now using browser-in-browser trick

ID: 76077f59-bd5f-5ad2-9a43-a3de46a604bb

STIX ID: report--76077f59-bd5f-5ad2-9a43-a3de46a604bb

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-01-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trellix researchers observed active phishing campaigns targeting Facebook users that employ the Browser‑in‑the‑Browser (BitB) technique — a fake, iframe‑based login pop-up — combined with legitimate cloud hosting and URL shorteners to evade detection and harvest credentials or personal data; lures include copyright notices, account suspension threats, and fake Meta security messages, with recommendations to navigate to official sites and enable two‑factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.