Threat IntelligenceSep 9, 2026
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Phishing attacks use fake browser windows and rogue RMM tools for persistent access.
Summary
Huntress researchers have identified two phishing campaigns from August that employed a sophisticated Browser-in-the-Browser (BiTB) technique. These attacks presented victims with convincing fake browser windows, leading them to attacker-controlled websites. The attackers then leveraged legitimate Remote Monitoring and Management (RMM) tools, potentially disguised or misused, to gain persistent access to compromised devices.
Entities
Browser-in-the-Browser (product)Remote Monitoring and Management tools (product)Huntress (vendor)