Threats Tagged 'browser-in-the-browser'
View all threats tagged with 'browser-in-the-browser'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'browser-in-the-browser'
Click on any threat for detailed analysis and mitigation recommendations
Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain... Join the discussion | AlienVault OTX General | 09/09/2026, 15:55:36 UTC Added: 09/10/2026, 05:52:16 UTC |
A sophisticated phishing campaign is targeting YouTube creators using convincing fake copyright strike notifications. The attack dynamically pulls real channel data including profile pictures, subscriber counts, and recent videos to create personalized scare pages. Victims are funneled through a Browser-in-the-Browser attack displaying a fake Google sign-in that captures credentials. The operation functions as phishing-as-a-service, with multiple attackers sharing infrastructure and rotating domains to evade detection. Successful attacks result in complete Google account takeover, allowing hijackers to rebrand channels and livestream cryptocurrency scams to existing audiences. The kit automatically exempts channels with over three million subscribers to avoid detection by security teams. Join the discussion | AlienVault OTX General | 04/15/2026, 17:15:57 UTC Added: 04/15/2026, 17:16:50 UTC |
Showing 1 to 2 of 2 results