Browser-in-the-Browser Phishing Steals Microsoft 365 Logins
Key Takeaways A sophisticated Browser-in-the-Browser (BitB) phishing campaign is actively targeting Microsoft 365 users. The attack employs highly convincing fake OAuth login popups that mimic...
Key Takeaways
- A sophisticated Browser-in-the-Browser (BitB) phishing campaign is actively targeting Microsoft 365 users.
- The attack employs highly convincing fake OAuth login popups that mimic legitimate Microsoft sign-in screens, even adapting to the victim’s device.
- Successful attacks steal OAuth consent grants, providing attackers with persistent access to Microsoft 365 environments without needing the user’s password for subsequent access.
- The campaign is designed to bypass common security tools through anti-debugging measures, keyword fragmentation, and bot redirection.
Advanced BitB Phishing Campaign Targets Microsoft 365 Logins
A highly deceptive Browser-in-the-Browser (BitB) phishing campaign is currently underway, specifically designed to compromise Microsoft 365 user credentials. This sophisticated attack is engineered to be so convincing that even individuals with a strong technical background could inadvertently expose their login information.
Table Of Content
The core of the attack involves embedding a fabricated browser window directly within a malicious webpage. This fake window meticulously imitates a genuine Microsoft OAuth login prompt, complete with a seemingly legitimate URL in a spoofed address bar, a padlock icon, and authentic Microsoft branding. Victims who click “Sign in with Microsoft” on a compromised site are presented with this fabricated window and, believing it to be authentic, proceed to enter their login credentials.
Researchers from Unit 42, the threat intelligence and incident response division of Palo Alto Networks, uncovered the details of this campaign and shared their findings in a report with Cyber Security News (CSN). They emphasized that this phishing popup is far more advanced than a simple graphical overlay. It is draggable across the screen, a feature that enhances its realism by mimicking the behavior of a genuine operating system window. Furthermore, it utilizes OS and browser fingerprinting to customize its appearance for each victim’s device, making it exceptionally difficult to distinguish from a legitimate login interface.
A critical aspect making this campaign particularly dangerous is its ability to evade standard security defenses. The attackers have implemented mechanisms to block debugging attempts, fragment keywords to circumvent content filters, and redirect automated bots away from the malicious page. This allows the attack to bypass many conventional detection tools, ensuring it reaches human targets effectively.
The objective of this campaign is straightforward but highly damaging. Once a victim submits their credentials, the attacker captures the OAuth consent grant. This grant can then be exploited to gain persistent access to Microsoft 365 environments, long after the initial login attempt. This stolen token functions similarly to a session cookie, providing ongoing access without requiring the victim to re-enter their password.
Dissecting the New Browser-in-the-Browser Phishing Attack
The attack sequence begins when a user navigates to a webpage masquerading as a legitimate service that requires Microsoft authentication. Upon clicking a sign-in button, a deceptive popup window is dynamically generated within the current browser tab using HTML, CSS, and JavaScript. This fabricated window features a spoofed URL bar displaying a realistic Microsoft OAuth address, cultivating a false sense of security.
Unlike an authentic browser popup, which operates as an independent window managed by the operating system, this fraudulent window is merely a Document Object Model (DOM) element confined within the parent browser tab. However, the attackers have enhanced its sophistication by making it draggable, a feature that further blurs the line between fake and real, removing a key visual cue users might employ to identify a phishing attempt. The attackers’ use of OS and browser fingerprinting ensures that the popup’s fonts, styling, and overall behavior precisely match the victim’s actual system. After credentials are entered, they are covertly transmitted to an attacker-controlled server. Often, victims are then redirected to the genuine Microsoft login page, leading them to believe they simply made a typing error and prompting them to try again, unaware their credentials have already been compromised, as detailed in a Kaspersky blog post on BitB phishing.
We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://t.co/EbWNF7JDTp pic.twitter.com/BVBjucAsxG
— Unit 42 (@Unit42_Intel) June 8, 2026
The Persistent Threat of Captured OAuth Tokens
The severity of this attack stems from the consequences of stolen credentials. As security researcher DLTA highlighted in response to the Unit 42 discovery, the primary objective is the capture of the OAuth consent grant itself. This artifact can persist and function akin to a session cookie or an SSO refresh token, granting the attacker enduring access to various cloud environments, email accounts, and other interconnected services, as explained in the Unit 42 report.
This implies that even a password reset might not immediately revoke an attacker’s access if they already possess a valid session token. Organizations must actively monitor for active sessions originating from unrecognised locations or devices and promptly revoke any suspicious tokens.
What You Should Do
- Enable Phishing-Resistant Authentication: Prioritize the use of passkeys or FIDO2 hardware security keys for all accounts, especially those with access to sensitive data.
- Utilize Password Managers: Implement a reputable password manager. These tools will only autofill credentials on legitimate, recognized website origins, serving as a critical indicator of a fake login page.
- Implement Conditional Access Policies: For organizations, configure conditional access policies to restrict sign-ins to managed devices and trusted locations, adding a robust layer of defense.
- Educate Users: Conduct regular training to raise awareness about advanced phishing techniques, including BitB attacks, and teach users how to identify suspicious login prompts.
- Monitor for Suspicious Sessions: Regularly review active user sessions and access logs within Microsoft 365 and other critical services for unusual activity or unknown device connections.
- Revoke Suspicious Tokens: Be prepared to immediately revoke OAuth tokens or session cookies associated with any suspected compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.