Cyber-security analysts are warning of a sophisticated credential-harvesting campaign that combines a deceptive “I’m not arobot” CAPTCHA prompt with a Browser-in-the-Browser (BitB) overlay to mimic Facebook’s login window.
The multi-stage lure is designed to harvest account credentials and session cookies from unsuspecting users.
<div> elements styled via CSS transform: scale(0.94) to appear slightly smaller than the parent viewport—creating the illusion of a separate browser dialog.POSTed to /gate.php on the attacker domain and immediately validated via the Facebook Graph API. Successful logins trigger the server to request a 2FA code or backup recovery tokens, which the page then re-prompts the user to enter. Stolen session cookies are shipped to a Telegram bot for real-time hijacking.| Artifact | Details |
|---|---|
| Registrar | Namecheap, created: 2025-07-03 |
| Malicious domains | cdn-recaptcha-validation[.]com, fb-login-secure[.]net |
| C2 IP | 185.180.199.54 (AS9009, M247) |
| JS libraries | fingerprintjs-pro, sweetalert2 (modified), CryptoJS |
| SHA-256 of main JS | 9f3b8e6d9e8f4b7c3d0a12f4e6f9871b0e1c8d5b3a1f9576b1e4ab3c7d9e8f6 |
BitB attacks exploit users’ trust in familiar UI chrome. Because the “window” resides entirely within the current tab, it bypasses browser defenses, such as anti-spoofing in the address bar and certificate indicators.
Security-conscious users who typically hover over URLs may still be fooled—the forged bar displays a valid padlock icon rendered from Feather icons.
Researchers at Huntress Labs note that the kit’s codebase overlaps with last year’s Steam BitB campaign, suggesting a commoditized phishing-as-a-service model.
With CAPTCHA gates lowering suspicion and BitB windows bypassing visual checks, hybrid lures like this are expected to proliferate.
Until browsers can cryptographically bind window chrome to origin, user vigilance and strong, phishing-resistant authentication remain the best defense.
PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version…
Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…
Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…
Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…
Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…
Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…