Browser-in-the-Middle attacks: How fake browsers steal MFA-protected accounts

Lana Kuzmina
September 26, 2025
Threat Intelligence
4 mins

Key takeaways

  • Browser-in-the-Middle (BitM) attacks use fake, pixel-perfect browser windows to steal credentials and bypass MFA.
  • Attackers rely on social engineering, such as fake copyright claims and bogus CAPTCHAs, to trick victims.
  • URL legitimacy alone is no longer enough to confirm authenticity, requiring layered defenses.

What is a Browser-in-the-Middle (BitM) attack?

Attackers are actively rendering fake, pixel-perfect browser windows inside legitimate browsers to steal Meta and Facebook credentials. This Browser-in-the-Middle (BitM) phishing campaign, tracked by Palo Alto Networks’ Unit42 since at least April 2025, bypasses traditional indicators of trust to harvest MFA-protected sessions.

The campaign typically starts with a phishing link in an email (often a faux copyright or policy notice) that redirects a victim to a fake CAPTCHA page. Interacting with the CAPTCHA triggers an in‑page fake browser window, a deceptive browser interface rendered inside the legitimate browser, that impersonates Facebook pop-up login windows and displays what looks like a legitimate URL while capturing credentials.

The attack still depends on social engineering, tricking the victim into clicking the malicious link and interacting with the fake page.

How does a BitM attack flow work?

The chain begins with social engineering and a shortened link.

The redirect lands the user on a bogus CAPTCHA page that, when interacted with, spawns a fake browser UI inside the real browser. The victim completes login and MFA inside that proxied browser. The attacker records the authenticated session (via cookies or by exporting the browser profile) and may then replay or resume it.

Why do BitM social engineering tactics succeed?

First comes emotional pressure: a copyright claim or account-suspension warning pushes people toward quick action.

Impersonating a major platform (Facebook/Meta) leverages strong recognition and the expectation of legitimate, familiar login flows.

A fake CAPTCHA lowers suspicion, since users are accustomed to clicking “I’m not a robot” to continue.

How BiTM adapt to Browser type and OS https://x.com/Unit42_Intel/status/1970926427819106392

While this campaign currently focuses on Meta's ecosystem, the underlying tactics, techniques, and procedures (TTPs) are highly adaptable. They can be easily repurposed to target other platforms where account access is valuable.

How can you defend against BitM attacks?

This ongoing campaign showcases how Browser-in-the-Middle (BitM) phishing is evolving into a turnkey method for stealing MFA-protected sessions, leveraging social engineering, redirect chains, and fake browser environments. Compounding the threat, the campaign frequently rotates domains, making detection and blocking significantly more difficult.

The key takeaway: URL legitimacy alone is no longer sufficient to determine authenticity. Organizations must adopt layered defenses to protect against these sophisticated phishing threats.

revel8 equips your employees with the practical knowledge and skills to recognize and respond to advanced phishing techniques like BitM before damage is done, ensuring you stay ahead of these evolving tactics.

Frequently Asked Questions

What is a Browser-in-the-Middle (BitM) attack?

A Browser-in-the-Middle (BitM) attack is an advanced phishing technique where attackers render a fake, pixel-perfect browser window inside a victim’s legitimate browser. This deceptive interface is used to capture credentials and bypass multi-factor authentication.

How does a BitM attack bypass MFA?

When a user enters their credentials and completes the MFA prompt within the fake browser window, the attacker captures the authenticated session cookies or profile. The attacker can then replay or resume the session to gain unauthorized access, bypassing the need for the physical MFA token.

How can organizations protect against BitM attacks?

URL legitimacy is no longer sufficient since the fake browser window may display a legitimate-looking URL. Organizations should implement layered security defenses and provide practical training to help employees recognize emotional pressure tactics, fake CAPTCHAs, and deceptive browser elements.

Sources

Related Articles

07.08.2026
Threat Intelligence
4 mins

How Calendar Phishing Bypasses Your Inbox Defenses

threat-intelligence
25.06.2026
Threat Intelligence
4 mins

Spam Bombing: The Opening Move Attackers Are Counting On

threat-intelligence
13.05.2026
Threat Intelligence
4 mins

When Breach Notifications
Become the Breach

threat-intelligence
White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?

Lana Kuzmina
Threat Intelligence Analyst