Hackers Use Browser-in-the-Browser Technique to Steal Facebook Login Credentials

Facebook’s massive user base of over 3 billion active users makes it a prime target for sophisticated phishing attacks.

Security researchers recently identified a significant surge in Facebook phishing scams during the second half of 2025, with attackers employing an advanced method called the “Browser-in-the-Browser” (BitB) technique to harvest user credentials at scale.

The Browser-in-the-Browser Attack

The BitB technique represents a significant escalation in phishing sophistication. Attackers create a custom-built, fake login window that appears within the victim’s legitimate browser tab, mimicking authentic Facebook authentication prompts.

Fake BitB facebook login
Fake BitB facebook login

The fake pop-up window displays an absolute Facebook URL, making it nearly indistinguishable from genuine login screens to unsuspecting users.

The attack typically begins with a phishing email disguised as a communication from a law firm, featuring fake legal notices about infringing content.

These emails contain shortened URLs that redirect victims to fake Meta captcha pages, adding an extra layer of deception before presenting the fraudulent Facebook login prompt.

Fake facebook HTML code
Fake facebook HTML code

Attackers have evolved their approach by exploiting legitimate cloud platforms to host phishing pages. Services like Netlify and Vercel are being abused to deliver credential harvesting forms that initially request basic information, full name, email address, phone number, and date of birth, before prompting for account passwords.

URL shorteners such as Lnk[.]ink and rebrand[.]ly are employed to mask phishing destinations and bypass traditional security filters.This abuse of trusted infrastructure lends false legitimacy to malicious pages while evading detection systems.

 Meta copyright/trademark violation
 Meta copyright/trademark violation

Attackers leverage multiple social engineering tactics, including fake account suspension notices, unauthorized login alerts, and security update requirements. Each theme exploits user anxiety about account security to prompt immediate action.

The key defense against these sophisticated attacks is skepticism. Verify login requests through official Facebook channels, never enter credentials through pop-up windows, and check URLs carefully.

Trellix research indicates that two-factor authentication continues to provide strong protection against account takeovers, even in cases of credential exposure.

Organizations should educate users about these evolving threats while implementing advanced email security solutions to filter phishing messages at the gateway.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories