ISEC7 Digital Workplace Blog

Browser-in-the-Browser (BITB) Attacks Explained

Written by Remi Keusseyan | May 17, 2022, 7:30:00 AM

Reviewed and updated in October 2026.

As cyberattacks grow more sophisticated, phishing has moved on from convincing emails, text messages and phone calls to convincing single sign-on (SSO) prompts that can expose your corporate users. One technique you should know about is the browser-in-the-browser (BITB) attack. It takes advantage of the SSO sign-in flow used by most organizations.

The security researcher mr.d0x described the technique in March 2022 and published templates that show how little effort it takes.

What is single sign-on?

Whenever we access public or corporate resources and services, we are asked to authenticate.

To simplify that process and strengthen security, users authenticate once against a central identity provider (IdP) with their work credentials, usually their email address. They can then access many websites and services, on-premises or in the cloud, without signing in again. This mechanism is called single sign-on (SSO).

The sign-in window typically appears as a pop-up browser window, for example the Microsoft 365 sign-in window that asks for your work account.

At this point, most people take it for granted that the window comes from a known, trusted vendor, in this case Microsoft, and enter their credentials without thinking twice. That is where browser-in-the-browser attacks come into play.

How does a BITB attack work?

A BITB attack is an advanced phishing attack that abuses the SSO sign-in flow to spoof a legitimate domain. It recreates the entire process with a fake browser window, drawn inside the web page, that makes users believe they are authenticating against a legitimate identity provider such as Microsoft, while they are in fact handing their credentials to an attacker. What makes it so dangerous is that the fake window, including its address bar, is almost impossible to tell apart from a real one with the naked eye.

Say an employee wants to use an external service, for example an online learning platform, that is connected to the company's identity provider, for example Google, through SSO. Employees do not have to create yet another account and password; they simply use their everyday corporate account. If they are already signed in to other corporate services in their browser, they may not even be asked for their credentials again. So far, so good.

If the employee lands on a spoofed site instead, they may see a window that looks exactly like the familiar Google sign-in. When prompted, they send their credentials not to their trusted provider but to an attacker, who can later use them to access the account and steal data.

Some identity providers are easier to imitate than others. Google, for example, is used for both private accounts (Gmail) and work accounts (Google Workspace), whereas other providers are mostly used for work-related services only.

How to protect your organization

The obvious answer would be to stop using SSO. In practice, that would make users' working lives harder, because they would need separate credentials for every on-premises and cloud service. That backfires: users stop using the services or reuse the same simple password for every account, which weakens the company's overall security.

Instead, pair your SSO process with Multi-Factor Authentication (MFA), and choose the method carefully. One-time codes and push approvals raise the bar considerably, but a phishing page can relay them to the real service in real time. Phishing-resistant methods such as FIDO2 security keys or passkeys are bound to the legitimate domain and do not work on a spoofed page. Conditional Access policies add another layer by allowing sign-ins only from managed, compliant devices.

A password manager helps too. The fake window is not a real browser window, and the actual address of the page does not match the one stored for the service, so the password manager will not offer to fill in the credentials. If autofill suddenly does not work on a familiar sign-in window, that is a warning sign.

There is also a simple check users can do themselves: try to drag the sign-in window outside the browser window. A real pop-up can be moved freely across the screen; a fake one drawn inside the page cannot leave it.

Educate your employees

When it comes to phishing, your employees are your first and last line of defense.

They need proper security awareness training so they can spot, or at least question and double-check, any unusual email, text message or pop-up asking for their credentials. Teach both technical staff and employees how these attacks work and which basic checks confirm or rule out a suspicious sign-in window. When in doubt, employees should report it to the IT security team straight away. Our articles Why Training Is Important and Best Practice: Cybersecurity Awareness go into more detail.

What to remember

Educating your employees so they recognize the hallmarks of a browser-in-the-browser attack is one of the most important steps you can take. Combine it with phishing-resistant MFA for your SSO process and an enterprise password manager. How stronger identity management helps against phishing in general is covered in How to Thwart Phishing Attacks with Enhanced Identity Management, and the basics of identity and access management in Demystifying Security: Identity and Access Management (IAM).

Want to know how well your sign-in processes hold up against phishing? Our endpoint security team will help you assess them and choose the next steps. Contact us.