Malware creators associated with a Phishing-as-a-Service (PhaaS) known as Sneaky 2FA have incorporated Browser-in-the-Browser (BitB) functionality into their arsenal, highlighting the continued evolution of such kits and making it easier for less experienced malicious users to carry out attacks on a large scale.
See also: New phishing campaign targets hotel customers

Push Securitysaid it had observed the technique being used in phishing attacks designed to steal victims' Microsoft account credentials.
BitB was first documented by security researcher mr.d0x in March 2022, describing how it is possible to use a combination of HTML and CSS code to create fake browser windows that can be masqueraded as login pages for legitimate services, in order to facilitate credential theft.
To complete the deception, the browser pop-up shows a legitimate Microsoft login URL, giving the victim the impression that they are entering credentials on a legitimate page, when in fact it is a phishing page.
In one attack chain observed by the company, users who land on a suspicious URL (“previewdoc[.]us”) are served with a Cloudflare Turnstile check. Only after the user passes the botnet check does the attack proceed to the next stage, which involves displaying a page with a “Sign in with Microsoft” button to view a PDF document.
Once clicked, a phishing page masquerading as a Microsoft login form is loaded into an embedded browser using the BitB technique, ultimately exporting the entered information and session details to the attacker, who can then use them to take control of the victim's account.
See also: How attackers turn SVG files into phishing bait

In addition to using bot protection technologies like CAPTCHA and Cloudflare Turnstile to prevent security tools from accessing phishing pages, attackers use conditional loading techniques to ensure that only intended targets can access them, while filtering out the rest or redirecting them to harmless sites.
Sneaky 2FA, first spotted by Sekoia earlier this year, is known to employ a variety of methods to resist analysis, including the use of obfuscation and disabling browser developer tools to thwart attempts to inspect websites. Additionally, phishing domains rotate quickly to minimize detection.
The revelation comes as part of research that found that it is possible to use a malicious browser extension to spoof registration and passkey logins, thereby allowing malicious users to access enterprise applications without the user's device or biometrics.
The Passkey Pwned, as it's called, exploits the fact that there is no secure communication channel between a device and the service and that the browser, which acts as an intermediary, can be manipulated through a malicious script or extension, essentially hijacking the authentication process.
See also: Quantum Route Redirect: Phishing service targets Microsoft 365 users

When registering or authenticating on websites using passkeys, the website communicates through the web browser by calling WebAuthn APIs such as navigator.credentials.create() and navigator.credentials.get(). The attack manipulates these flows via JavaScript injection.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
