Back to all lessons
Awareness Lessons
last month

Fake Browser Windows and Rogue RMM Tools Enable Persistent Phishing Attacks

Attackers used Browser-in-the-Browser (BiTB) phishing techniques to render convincing fake browser windows that tricked users into entering credentials on attacker-controlled sites. Once initial access was achieved, threat actors abused legitimate Remote Monitoring and Management (RMM) tools to establish persistent footholds — a tactic that blends malicious activity into normal IT operations traffic. This matters because RMM tool abuse is increasingly difficult to detect, as these tools are trusted by default in many enterprise environments. The combination of social engineering and living-off-the-land techniques dramatically raises the bar for both user vigilance and security tooling.

Tactical Insight

Immediate actions

  • Train all users to verify browser URL authenticity and recognize BiTB phishing indicators such as non-interactive address bars or pop-up windows that cannot be moved outside the browser viewport.
  • Audit and restrict which RMM tools are authorized for use in your environment, blocking unapproved or shadow RMM binaries at the endpoint level.

Long-term improvements

  • Implement application allowlisting to prevent unauthorized RMM clients or remote access tools from executing on endpoints.
  • Enforce phishing-resistant MFA (e.g., FIDO2/passkeys) across all user accounts to reduce the impact of credential theft from phishing campaigns.
  • Establish a formal acceptable-use policy for RMM tools that includes periodic revalidation of all authorized remote access software.

Detection measures

  • Deploy behavioral detection rules in your SIEM/EDR to alert on RMM tool installations or executions that originate outside of standard IT provisioning workflows.
  • Monitor network traffic for unexpected outbound connections to RMM command-and-control infrastructure using threat intelligence feeds and DNS filtering.