Technology is constantly evolving, and so are cyber threats. The long-standing Man-in-the-Browser (MitB) technique is making a comeback in 2025, making credential theft more sophisticated and difficult to detect. While MitB attacks used to require basic login monitoring on banking sites, today criminals are using AI-driven scripting, session hijacking , and dynamic payloads to gain access to accounts in real time.

What is Man-in-the-Browser and why does it return dynamically?
MitB is a type of attack where malware is installed inside the victim's browser and monitors or modifies data exchanged with legitimate websites. The main difference with classic phishing is that attackers can bypass traditional filters and HTTPS, capturing credentials, OTPs (One-Time Passwords), and other sensitive data in real time.
See also: CyberVolk's new VolkLocker ransomware targets Linux and Windows
In 2025, MitB attacks are no longer limited to financial institutions. The target is any online service with multi-factor authentication (MFA), such as cloud tools, SaaS platforms, email, and data storage applications. The new generation of MitB kits includes modules that:
- They monitor sessions without requiring user interaction.
- They integrate AI for page type recognition and dynamic redirection of payloads.
- They use encryption layers to avoid detection by antivirus and EDR.

How criminals steal credentials in real time
Modern MitB attacks operate in three stages:
- Initial infection: The malware enters the browser via drive-by downloads, malicious extensions, or compromised extensions from popular marketplaces.
- Session Hijacking: Once the victim is connected to a service, the malware monitors credential entries and communications with the server, dynamically recognizing MFA prompts.
- Real-time credential theft: Credentials and passwords are sent to the criminal almost instantly, allowing them to connect to the victim simultaneously, bypassing any traditional alerts.
One of the most worrying developments is the ability of MitB malware to manipulate push-based MFA, such as notifications on mobile devices, by creating fake pages within the browser to capture passwords in real time.
See also: BlackForce: New phishing kit steals credentials through MitB attacks
Concealment and detection techniques
The new generation of MitB malware has evolved to evade security checks:
- Run in memory: They do not write data to disk, making detection by traditional antiviruses difficult.
- Anti-Sandbox mechanisms: Detect virtual environments, VM agents and sandbox detection tools.
- Dynamic JavaScript Injection: They adapt payloads depending on the domain the user is visiting, bypassing signatures and rules.
Organizations that do not monitor their users' sessions in real time are at increased risk of breach.
See also: MITRE: The 25 most dangerous software vulnerabilities of 2025

Protection and best practices
Tackling MitB requires a multi-layered strategy:
- Zero Trust Browsing: Limiting authorizations to only necessary procedures and controlling each session regardless of trust.
- Advanced EDR / XDR: Use behavioral analysis for real-time detection of suspicious login patterns and session hijacking.
- Browser Hardening: Disabling unnecessary extensions, sandboxing for each profile and restricting script execution to trusted domains.
- User Awareness & MFA: Education about suspicious links, unique passwords, and use of hardware-based MFA (e.g. security keys) instead of push-based notifications.
- Threat Intelligence: Monitoring emerging MitB kits, shared IoCs (Indicators of Compromise) and threat feeds for proactive defense.
The Future of Man-in-the-Browser
In 2025, MitB technology combines AI, dynamic injection, and cross-platform capabilities, creating an environment where even experienced users can fall victim. The critical point for companies and organizations is to combine technical measures with awareness and continuous monitoring to reduce the attack surface and prevent real-time account breaches.
With these developments, traditional security with antivirus and static firewalls is unable to cope with the threat. The new norm is proactive, behavior-driven, multi-layered cybersecurity, where every session is considered potentially offensive until proven otherwise.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
