Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/Threats/Browser-in-the-Browser Phishing Steals Microsoft 365 Logins
Threats

Browser-in-the-Browser Phishing Steals Microsoft 365 Logins

Key Takeaways A sophisticated Browser-in-the-Browser (BitB) phishing campaign is actively targeting Microsoft 365 users. The attack employs highly convincing fake OAuth login popups that mimic...

Emy Elsamnoudy
Emy Elsamnoudy
June 9, 2026 4 Min Read
48 0

Key Takeaways

  • A sophisticated Browser-in-the-Browser (BitB) phishing campaign is actively targeting Microsoft 365 users.
  • The attack employs highly convincing fake OAuth login popups that mimic legitimate Microsoft sign-in screens, even adapting to the victim’s device.
  • Successful attacks steal OAuth consent grants, providing attackers with persistent access to Microsoft 365 environments without needing the user’s password for subsequent access.
  • The campaign is designed to bypass common security tools through anti-debugging measures, keyword fragmentation, and bot redirection.

Advanced BitB Phishing Campaign Targets Microsoft 365 Logins

A highly deceptive Browser-in-the-Browser (BitB) phishing campaign is currently underway, specifically designed to compromise Microsoft 365 user credentials. This sophisticated attack is engineered to be so convincing that even individuals with a strong technical background could inadvertently expose their login information.

Table Of Content

  • Key Takeaways
  • Advanced BitB Phishing Campaign Targets Microsoft 365 Logins
  • Dissecting the New Browser-in-the-Browser Phishing Attack
  • The Persistent Threat of Captured OAuth Tokens
  • What You Should Do

The core of the attack involves embedding a fabricated browser window directly within a malicious webpage. This fake window meticulously imitates a genuine Microsoft OAuth login prompt, complete with a seemingly legitimate URL in a spoofed address bar, a padlock icon, and authentic Microsoft branding. Victims who click “Sign in with Microsoft” on a compromised site are presented with this fabricated window and, believing it to be authentic, proceed to enter their login credentials.

Researchers from Unit 42, the threat intelligence and incident response division of Palo Alto Networks, uncovered the details of this campaign and shared their findings in a report with Cyber Security News (CSN). They emphasized that this phishing popup is far more advanced than a simple graphical overlay. It is draggable across the screen, a feature that enhances its realism by mimicking the behavior of a genuine operating system window. Furthermore, it utilizes OS and browser fingerprinting to customize its appearance for each victim’s device, making it exceptionally difficult to distinguish from a legitimate login interface.

A critical aspect making this campaign particularly dangerous is its ability to evade standard security defenses. The attackers have implemented mechanisms to block debugging attempts, fragment keywords to circumvent content filters, and redirect automated bots away from the malicious page. This allows the attack to bypass many conventional detection tools, ensuring it reaches human targets effectively.

The objective of this campaign is straightforward but highly damaging. Once a victim submits their credentials, the attacker captures the OAuth consent grant. This grant can then be exploited to gain persistent access to Microsoft 365 environments, long after the initial login attempt. This stolen token functions similarly to a session cookie, providing ongoing access without requiring the victim to re-enter their password.

Dissecting the New Browser-in-the-Browser Phishing Attack

The attack sequence begins when a user navigates to a webpage masquerading as a legitimate service that requires Microsoft authentication. Upon clicking a sign-in button, a deceptive popup window is dynamically generated within the current browser tab using HTML, CSS, and JavaScript. This fabricated window features a spoofed URL bar displaying a realistic Microsoft OAuth address, cultivating a false sense of security.

Unlike an authentic browser popup, which operates as an independent window managed by the operating system, this fraudulent window is merely a Document Object Model (DOM) element confined within the parent browser tab. However, the attackers have enhanced its sophistication by making it draggable, a feature that further blurs the line between fake and real, removing a key visual cue users might employ to identify a phishing attempt. The attackers’ use of OS and browser fingerprinting ensures that the popup’s fonts, styling, and overall behavior precisely match the victim’s actual system. After credentials are entered, they are covertly transmitted to an attacker-controlled server. Often, victims are then redirected to the genuine Microsoft login page, leading them to believe they simply made a typing error and prompting them to try again, unaware their credentials have already been compromised, as detailed in a Kaspersky blog post on BitB phishing.

We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://t.co/EbWNF7JDTp pic.twitter.com/BVBjucAsxG

— Unit 42 (@Unit42_Intel) June 8, 2026

The Persistent Threat of Captured OAuth Tokens

The severity of this attack stems from the consequences of stolen credentials. As security researcher DLTA highlighted in response to the Unit 42 discovery, the primary objective is the capture of the OAuth consent grant itself. This artifact can persist and function akin to a session cookie or an SSO refresh token, granting the attacker enduring access to various cloud environments, email accounts, and other interconnected services, as explained in the Unit 42 report.

This implies that even a password reset might not immediately revoke an attacker’s access if they already possess a valid session token. Organizations must actively monitor for active sessions originating from unrecognised locations or devices and promptly revoke any suspicious tokens.

What You Should Do

  • Enable Phishing-Resistant Authentication: Prioritize the use of passkeys or FIDO2 hardware security keys for all accounts, especially those with access to sensitive data.
  • Utilize Password Managers: Implement a reputable password manager. These tools will only autofill credentials on legitimate, recognized website origins, serving as a critical indicator of a fake login page.
  • Implement Conditional Access Policies: For organizations, configure conditional access policies to restrict sign-ins to managed devices and trusted locations, adding a robust layer of defense.
  • Educate Users: Conduct regular training to raise awareness about advanced phishing techniques, including BitB attacks, and teach users how to identify suspicious login prompts.
  • Monitor for Suspicious Sessions: Regularly review active user sessions and access logs within Microsoft 365 and other critical services for unusual activity or unknown device connections.
  • Revoke Suspicious Tokens: Be prepared to immediately revoke OAuth tokens or session cookies associated with any suspected compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Microsoft June 2026 Patch Tuesday Fixes 198 Flaws, Including 3 Zero-Days

Next Post

MagicAd Android Malware Bypasses Restrictions, Floods Devices with Ads

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us