Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Phishing Scams Exploit Browser Attacks to Steal Facebook Passwords
News

Phishing Scams Exploit Browser Attacks to Steal Facebook Passwords

Team-CWDBy Team-CWDJanuary 13, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybercriminals are using are increasingly using a sneaky browser-in-the-browser (BitB) attack technique in efforts to steal login credentials of Facebook users.

According to analysis by cybersecurity researchers at Trellix, there has been a surge in attackers distributing phishing emails which lure users towards trustworthy looking authentication screens with the intention of harvesting usernames and passwords.

It is thought that the aim of the attacks is to takeover accounts to steal personal data, commit identity fraud or spread scams to the users’ contacts. With over three billion users, Facebook remains a tempting target for cyber criminals to undertake attacks and scams.

These campaigns typically begin with phishing emails: researchers noted that attackers commonly distribute lures claiming to be messages from law firms warning potential victims that they need to take urgent action to avoid a claim of copyright infringement.

Other lures known to be distributed by the attackers issue fake notifications about an unauthorized login attempt or a warning that the account is about to be shutdown due to suspicious activity.

Each of these is designed to force the user to panic and take what they’re being told is the necessary action to prevent their account from being closed.

The phishing emails urge the user to click what looks like a Facebook link to take the necessary action – although these are phoney shortened URLs which are manipulated to look more legitimate.

What makes the attacks seem convincing is how the browser-in-the-browser pop-up windows looks legitimate and exactly how users would expect the Facebook login page to appear.

The pop-up browser contains the real Facebook login page URL, something the attackers have hardcoded into the authentication window, while the attackers also deploy a fake CAPTCHA window before this. Both tactics are designed to trick the victim into believing they’re visiting a real Facebook login page.

These ‘appeal’ pages ask the users for personal information, including their name, email address, phone number and date of birth – before a second page asks them to ‘confirm’ their password.

Through these fake pages, the attackers gain access to sensitive personal information, usernames and passwords they can use to commit further fraud at the victims’ expense.

“By creating a custom-built, fake login pop-up window within the victim’s browser, this method capitalizes on user familiarity with authentication flows, making credential theft nearly impossible to detect visually,” said Trellix.

To help counter phishing attacks like this, it’s recommended that users apply two-factor authentication (2FA) to accounts: this can automatically block account takeover, even if cyber-criminals steal legitimate login credentials.

It’s also recommended that users treat emails making sudden, unexpected requests like this with suspicion – and that if they are worried about a notification about their account, to login directly via Facebook from their browser, rather than following an unfamiliar link.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChina-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
Next Article WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Chronology of a Skype attack

February 5, 2026

Common Apple Pay scams, and how to stay safe

January 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.