Browser-in-the-browser phishing attacks have been observed, utilizing a tactic where an attacker creates a fake browser window within a webpage to deceive targets. The attack sequence involves a phishing message with a malicious link redirecting victims to a landing page, where they are asked to view files via Adobe Acrobat. After clicking on the prompt, targets are presented with a bitB page within the webpage, which looks like an official Adobe webpage. This fake page instructs the victim to download and install ScreenConnect, ultimately leading to the deployment of multiple rogue ScreenConnect instances on their endpoints.
The attackers use social engineering techniques to convince victims to take the bait at every stage of the attack. The bitB technique is not new but highlights how persistently threat actors work to deceive targets. The attack chain involves a CAPTCHA lure, bitB, and persistence, with the target being convinced to click on an embedded link in the email, which takes them to a fake CAPTCHA lure. This phishing landing page displays a fake "safe access" browser check, asking visitors to confirm their browser to continue securely.[/subscribe_to_unlock_form]
Browser-in-the-browser phishing attacks have been observed, utilizing a tactic where an attacker creates a fake browser window within a webpage to deceive targets. The attack sequence involves a phishing message with a malicious link redirecting victims to a landing page, where they are asked to view files via Adobe Acrobat. After clicking on the prompt, targets are presented with a bitB page within the webpage, which looks like an official Adobe webpage. This fake page instructs the victim to download and install ScreenConnect, ultimately leading to the deployment of multiple rogue ScreenConnect instances on their endpoints.
The attackers use social engineering techniques to convince victims to take the bait at every stage of the attack. The bitB technique is not new but highlights how persistently threat actors work to deceive targets. The attack chain involves a CAPTCHA lure, bitB, and persistence, with the target being convinced to click on an embedded link in the email, which takes them to a fake CAPTCHA lure. This phishing landing page displays a fake "safe access" browser check, asking visitors to confirm their browser to continue securely.[emaillocker id="1283"]
The significance of this attack lies in its ability to bypass social-engineering cues and deceive targets into downloading and installing rogue ScreenConnect instances. The attackers use legitimate domains and services to further avoid detection. The threat actors' motivation is unclear, but the campaign scale and victim counts are unknown. Defenders should be aware of this tactic and take necessary precautions to prevent similar attacks.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1070.004 | Indicator Removal | File Deletion |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]