Browser-in-the-browser. BitB.
when you click sign in with Google on a website. A popup appears that looks exactly like a real Chrome window correct Google URL in the address bar, correct design everything.
You type your credentials. They go to the attacker.
But there's no real window. it's a simulation. built with HTML, CSS, and JavaScript inside the existing webpage. The URL bar is an image. The padlock is an image. The entire "browser window" is a div element rendered on top of the page you're already on.
It was first demonstrated by a researcher mr.d0x(
@mrd0x) in 2022. But it's now appearing in real attacks. Steam gaming accounts. Microsoft 365. Facebook. It's now packaged into phishing-as-a-service kits, making it available to anyone.
It's hard to spot because the URL looks correct, and the window looks like it came from your OS. Your eyes have been trained to trust these things...
the one thing that catches it:
try to drag the popup window outside the browser. a real browser window moves freely. a BitB popup stops at the edge of the browser. it can't leave.
Also: password managers don't autofill BitB windows. if your password manager doesn't offer to fill in your credentials, something is wrong.