A publicly released Browser-in-the-Browser (BitB) phishing toolkit is making it easier to build fake Chrome-style pop-up windows that imitate legitimate single sign-on prompts from providers such as Google, Microsoft, and Apple. The templates, published by security researcher mr.d0x on GitHub and detailed on his site, allow attackers or red teams to customize browser window titles and displayed URLs so the phishing prompt appears to be a real browser-based authentication dialog.
The technique is designed to increase the credibility of credential-harvesting pages by mimicking familiar login flows inside a forged browser window, lowering the barrier to entry for less sophisticated operators. Reporting noted that BitB-style attacks had already been observed in earlier campaigns, including lures targeting Steam users, and warned that the approach can be paired with phishing frameworks such as Evilginx to capture credentials and potentially steal 2FA session data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Security researcher mr.d0x released Browser in the Browser phishing templates that simulate Chrome single sign-on popup windows for services such as Google, Microsoft, Apple, Twitter, and Steam. The templates allow customization of the displayed URL and window title and were presented as usable for red-team testing or phishing abuse.
Zscaler reported that fake gaming sites used the Browser in the Browser technique in attacks targeting Steam credentials. The article cites this as evidence that the technique was already in use before the later template release.
Kuba Gretzky, creator of the Evilginx phishing toolkit, tested the Browser in the Browser method with Evilginx and showed that it worked. This demonstrated that the fake browser-window technique could be combined with a phishing framework capable of capturing credentials and potentially 2FA session data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.