Skip to main content

New type of attack: browser in the browser


marcofabbri
Forum|alt.badge.img+13

Hi everyone,

just a quick update about a new type of attack: browser in the browser.

It simulates SSO popup windows to steal credentials with graphic html5 engine.

https://thehackernews.com/2022/03/new-browser-in-browser-bitb-attack.html

This is an example:

 

I’ll leave more info in next days about this attack when I found about it!

[UPDATE]

So it's a new type of attack (to say right, the first time it show itself was in 2020) called browser in the browser (BitB) attack. It's a midway to a phishing attack and social, because it relies on a miscalculation (hope it's the right word in english) of the user: it show up a pop-up windows rendered with HTML5 engine that's exacly the correct contropart.

It take advantage of all those SSO login or MFA authentication mechanisms that require user interaction.

A Facebook example was posted on Twitter by mr.d0x: https://twitter.com/mrd0x

"Combine the window design with an iframe pointing to the malicious server hosting the phishing page, and it's basically indistinguishable," mrd0x said in a technical write-up published last week "JavaScript can be easily used to make the window appear on a link or button click, on the page loading etc."

 

7 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8492 comments
  • April 12, 2022

It is amazing what they are coming up with now.  This is very interesting for sure and a good read.


marcofabbri
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 990 comments
  • April 12, 2022

I think this is scary, I viewed some examples where neither I can’t say if it’s real or phishing. Only an in-browser protection can block this type of attack.


JMeixner
Forum|alt.badge.img+17
  • On the path to Greatness
  • 2650 comments
  • April 12, 2022

Looks really like an original browser window. The bad guys get more tricky every day...


Rick Vanover
Forum|alt.badge.img+10
  • RICKATRON
  • 766 comments
  • April 13, 2022

Good share! Yes, the bad actors are getting smarter :)


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1352 comments
  • April 14, 2022
Rick Vanover wrote:

Good share! Yes, the bad actors are getting smarter :)

That's the problem. The better the security measures get, the better/smarter the attackers have to be...


marcofabbri
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 990 comments
  • April 14, 2022

I updated first post with more information!


marcofabbri
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 990 comments
  • July 26, 2022

This is an interesting video about this new type of attack: