Back to blog

The New Browser-in-the-Browser (BITB) Attack Makes Phishing Almost Undetectable

B
BlueSecure
Équipe BlueSecure
March 23, 20222 min read
The New Browser-in-the-Browser (BITB) Attack Makes Phishing Almost Undetectable

A new phishing technique called the Browser-in-the-Browser (BITB) attack can be used to simulate a browser window within the browser in order to spoof a legitimate domain name, making it possible to launch highly convincing phishing campaigns.
For example, a fake URL bar may display: https://login.microsoft.com.

According to a pentester known as @mrd0x on Twitter, the method takes advantage of third-party single sign-on (SSO) options built into applications, such as “Sign in with Google” (also available with LinkedIn, Office, Facebook …).

While the default behavior when a user attempts to log in through these methods is to be presented with a pop-up window to complete the authentication process, the Browser-in-the-Browser (BITB) attack aims to reproduce this entire process using a combination of HTML and CSS code to create a fully fabricated browser window styled after the target’s operating system.

It should be noted that this technique is difficult to adapt to mobile devices, as browsers do not currently support pop-ups on these devices, making the result less convincing.

This technique has been used before, but it appears to be becoming more widespread. In 2020, a cybersecurity research company disclosed details of a campaign that leveraged the BITB trick to steal Steam video game service credentials through fake websites resembling those of Counter-Strike: Global Offensive (CS: GO).

Although this method makes it considerably easier to build effective social engineering campaigns, it should be noted that potential victims must be redirected to a phishing domain capable of displaying such a fake authentication window to collect login credentials.

“But once on the attacker-owned site, the user will feel comfortable entering their credentials into what appears to be the legitimate website,” mrd0x added.

Link to the original article on mrd0x.com

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article