#bitb — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bitb, aggregated by home.social.
-
Waarschuwing voor "Browser in the Browser" aanvallen
Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:
https:⧸⧸accounts.google.com/signin/v3/
maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.
Onderin https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.
De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van https://www.virustotal.com/gui/domain/marriott-hiring.com). Als u zou openen (dat raad ik af):
https:⧸⧸marriott-hiring․com
moet u eerst een vinkje zetten, zogenaand om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.
De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).
Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.
#AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM
-
Waarschuwing voor "Browser in the Browser" aanvallen
Bij een BitB-aanval toont een nepwebsite een nep pop-up-venster dat eruit ziet als een (deels of geheel) nieuw browser-venster. Gesuggereerd wordt dat u uw inloggegevens moet invoeren op bijvoorbeeld:
https:⧸⧸accounts.google.com/signin/v3/
maar dat is allemaal fake: door u ingevoerde nloggegevens vallen zo in handen van de eigenaar van de onderliggende website, die daarmee als u kan inloggen en uw account kan kapen.
Onderin https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778 ziet u een lijst van criminele domeinnamen waar deze techniek op werd of nog wordt toegepast.
De hieronder getoonde website is gehost bij Amazon (zie het RELATIONS tabblad van https://www.virustotal.com/gui/domain/marriott-hiring.com). Als u zou openen (dat raad ik af):
https:⧸⧸marriott-hiring․com
moet u eerst een vinkje zetten, zogenaamd om te bevestigen dat u een mens bent. Daarna verschijnt het beeld dat linksonder te zien is.
De feitelijke BitB-aanval ziet u in het 2e plaatje (meer info onder ALT).
Nb. met een passkey is deze aanval niet mogelijk omdat de domeinnaam niet klopt. Zwakke 2FA (SMS, TOTP of Number Matching) voorkómt *niet* dat u slachtoffer wordt.
#AmazonIsEvil #BigTechIsEvil #LetsEncryptIsEvil #BitB #Phishing #NepWebSites #ATO #AccountTakeOver #AitM #MitM
-
Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025
Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link. Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...
-
Browser-in-the-Browser (BitB): Najczęstsza metoda ataku na użytkowników Facebooka w drugim półroczu 2025
Portale społecznościowe są często wybierane przez atakujących jako źródło dystrybucji malware. Cyberprzestępcy korzystając z reklam rozsyłają treści, które pod pozorem darmowych narzędzi, sensacyjnych materiałów wideo czy też zaskakujących promocji nakłaniają użytkowników do kliknięcia w link. Dalszy scenariusz ataku możemy sobie łatwo wyobrazić. Przejęcie konta, masowe wyłudzanie “na Blika”, utrata dostępu...
-
Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.
Highlights:
• Cloudflare Turnstile evasion
• Conditional loading → redirects scanners
• W3LL Panel OV6 code components
• Heavy HTML/JS obfuscation
• Domain rotation + URL maskingFollow for more threat intel updates.
#CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365
-
Sneaky2FA has added Browser-in-the-Browser (BITB) capabilities to display fake Microsoft login windows that match the victim’s OS and browser environment.
Highlights:
• Cloudflare Turnstile evasion
• Conditional loading → redirects scanners
• W3LL Panel OV6 code components
• Heavy HTML/JS obfuscation
• Domain rotation + URL maskingFollow for more threat intel updates.
#CyberSecurity #Phishing #BITB #Sneaky2FA #ThreatIntel #Microsoft365
-
Attackers are using “Sneaky 2FA” to create fake sign-in windows that look real https://www.malwarebytes.com/blog/news/2025/11/attackers-are-using-sneaky-2fa-to-create-fake-sign-in-windows-that-look-real #Sneaky2FA #phishing #Privacy #Scams #News #BitB
-
Attackers are using “Sneaky 2FA” to create fake sign-in windows that look real https://www.malwarebytes.com/blog/news/2025/11/attackers-are-using-sneaky-2fa-to-create-fake-sign-in-windows-that-look-real #Sneaky2FA #phishing #Privacy #Scams #News #BitB
-
The Boys are LIVE on this Thursday with a proper UFC 316 preview! #BitB
@[email protected] @[email protected]
Join us! 🤝
-
Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)
Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...
#WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam
-
Cyberprzestępcy kradną konta Steam graczy CS2 za pomocą techniki Browser-in-the-Browser (BitB)
Kilka dni temu zespół Silent Push poinformował o namierzeniu kampanii phishingowej targetującej graczy Counter-Strike 2 na Steam z wykorzystaniem techniki Browser-in-the-Browser (BitB). Technika BitB została stworzona w 2022 roku przez eksperta security mr. d0xa (na githubie wciąż udostępnia template ataku). Na czym polega? Na niektórych stronach mamy możliwość zalogowania za...
#WBiegu #Bitb #BrowserInTheBrowser #Cyberawareness #KradzieżDanych #OSINT #Phishing #Steam
-
The Boys are LIVE on this Thursday with a proper UFC London preview 🇬🇧 #BitB
@[email protected] @[email protected]
Come hang 🤝
https://x.com/i/broadcasts/1… -
Bitcoin ETFs end three-day skid with $254M inflow - The $254 million inflow day was the third-largest ever on days when Blac... - https://cointelegraph.com/news/bitcoin-etfs-end-three-day-skid-with-254-million-inflow #ethereumetfflows #farsideinvestors #bitcoinetfflows #ibit #fbtc #bitb #arkb
-
Bitcoin ETFs end three-day skid with $254M inflow - The $254 million inflow day was the third-largest ever on days when Blac... - https://cointelegraph.com/news/bitcoin-etfs-end-three-day-skid-with-254-million-inflow #ethereumetfflows #farsideinvestors #bitcoinetfflows #ibit #fbtc #bitb #arkb
-
Bitcoin ETFs see $28.6M inflows after 8-day outflow streak - Three spot Bitcoin ETF issuers saw an inflow on Sept. 9 — but it didn’t ... - https://cointelegraph.com/news/us-bitcoin-etfs-28-million-inflow #farsideinvestors #spotbitcoinetf #invescogalaxy #ark21shares #fidelity #bitwise #outflow #inflow #fbtc #bitb #arkb #btco
-
Bitcoin ETFs see $28.6M inflows after 8-day outflow streak - Three spot Bitcoin ETF issuers saw an inflow on Sept. 9 — but it didn’t ... - https://cointelegraph.com/news/us-bitcoin-etfs-28-million-inflow #farsideinvestors #spotbitcoinetf #invescogalaxy #ark21shares #fidelity #bitwise #outflow #inflow #fbtc #bitb #arkb #btco
-
US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - https://news.bitcoin.com/us-bitcoin-etfs-see-fourth-day-of-outflows-totaling-152m/ #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl
-
US Bitcoin ETFs See Fourth Day of Outflows, Totaling $152M - U.S. spot bitcoin exchange-traded funds (ETFs) experienced another day of outflows... - https://news.bitcoin.com/us-bitcoin-etfs-see-fourth-day-of-outflows-totaling-152m/ #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl
-
US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - https://news.bitcoin.com/us-spot-bitcoin-etfs-face-third-day-of-outflows-145-million-drained-on-monday/ #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl
-
US Spot Bitcoin ETFs Face Third Day of Outflows, $145 Million Drained on Monday - U.S. spot bitcoin exchange-traded funds (ETFs) experienced their third consecutive... - https://news.bitcoin.com/us-spot-bitcoin-etfs-face-third-day-of-outflows-145-million-drained-on-monday/ #u.s.spotbitcoinetfs #tradevolume #arkinvest #fidelity #outflows #finance #bitcoin #bitwise #vaneck #arkb #bitb #etfs #fbtc #hodl
-
Grayscale’s GBTC and Vaneck’s HODL Report Outflows as US Bitcoin ETFs Gain $50M - On Friday, U.S. spot bitcoin exchange-traded funds experienced their 14th consecut... - https://news.bitcoin.com/grayscales-gbtc-and-vanecks-hodl-report-outflows-as-us-bitcoin-etfs-gain-50m/ #cryptocurrency #btcholdings #tradevolume #blackrock #grayscale #fidelity #finance #bitcoin #crypto #arkb #bitb #etfs #fbtc #gbtc #ibit
-
Grayscale’s GBTC and Vaneck’s HODL Report Outflows as US Bitcoin ETFs Gain $50M - On Friday, U.S. spot bitcoin exchange-traded funds experienced their 14th consecut... - https://news.bitcoin.com/grayscales-gbtc-and-vanecks-hodl-report-outflows-as-us-bitcoin-etfs-gain-50m/ #cryptocurrency #btcholdings #tradevolume #blackrock #grayscale #fidelity #finance #bitcoin #crypto #arkb #bitb #etfs #fbtc #gbtc #ibit
-
Blackrock’s IBIT and Fidelity’s FBTC Drive $28M Inflows for US Bitcoin ETFs - On Wednesday, U.S. spot bitcoin exchange-traded funds (ETFs) continued their strea... - https://news.bitcoin.com/blackrocks-ibit-and-fidelitys-fbtc-drive-28m-inflows-for-us-bitcoin-etfs/ #cryptocurrency #btcholdings #tradevolume #blackrock #grayscale #fidelity #finance #bitcoin #crypto #arkb #bitb #etfs #fbtc #gbtc #ibit
-
Blackrock’s IBIT and Fidelity’s FBTC Drive $28M Inflows for US Bitcoin ETFs - On Wednesday, U.S. spot bitcoin exchange-traded funds (ETFs) continued their strea... - https://news.bitcoin.com/blackrocks-ibit-and-fidelitys-fbtc-drive-28m-inflows-for-us-bitcoin-etfs/ #cryptocurrency #btcholdings #tradevolume #blackrock #grayscale #fidelity #finance #bitcoin #crypto #arkb #bitb #etfs #fbtc #gbtc #ibit
-
Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - https://cointelegraph.com/news/grayscale-gbtc-inflows-record-bitcoin-exchange-traded-fund-etf #franklintempleton #fbtc #bitb
-
Grayscale’s GBTC stops bleeding: First inflow since launch - Grayscale Investments' GBTC has seen its first day of inflows, following... - https://cointelegraph.com/news/grayscale-gbtc-inflows-record-bitcoin-exchange-traded-fund-etf #franklintempleton #fbtc #bitb
-
❌ Nowa scam-kampania w Polsce wykorzystująca sprytną technikę BITB. Zobacz szczegóły żeby nie dać się nabrać
Czy widzisz w adresie na zdjęciu poniżej coś podejrzanego? …wygląda on zupełnie dobrze ✅ a mimo tego ta strona 🔴 wykrada dane. Jak to możliwe? To sprytna technika ataku o nazwie Browser In The Browser („przeglądarka w przeglądarce”). Świeżą kampanię, która wykorzystuje BITB, opisuje właśnie KNF. 1️⃣ Najpierw do ofiary...
-
Browser In The Browser (BitB) sin marcos https://blog.elhacker.net/2024/02/browser-in-browser-bitb-sin-marcos-frames.html #evilginx2 #phishing #bitb
-
A new approach to Browser In The Browser (#BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login pages like #Microsoft and the use with #Evilginx. : https://github.com/waelmas/frameless-bitb?fbclid=IwAR1UGSiByeRZWUtxXkSb-zrNRTgmyXtbcp7s0dxZsThyeDPLmsLC5pOFiV8
-
Bitwise Leads the Way as First US Bitcoin ETF to Publicly Disclose Wallet Address - On Wednesday, Jan. 24, 2024, Bitwise, a leading digital asset manager, made a grou... - https://news.bitcoin.com/bitwise-leads-the-way-as-first-us-bitcoin-etf-to-publicly-disclose-wallet-address/ #spotbitcoinetfs #cryptocurrency #bitcoin(btc) #bitcoinetf #bitwise #crypto #news #bitb
-
Bitwise Leads the Way as First US Bitcoin ETF to Publicly Disclose Wallet Address - On Wednesday, Jan. 24, 2024, Bitwise, a leading digital asset manager, made a grou... - https://news.bitcoin.com/bitwise-leads-the-way-as-first-us-bitcoin-etf-to-publicly-disclose-wallet-address/ #spotbitcoinetfs #cryptocurrency #bitcoin(btc) #bitcoinetf #bitwise #crypto #news #bitb
-
Arkham Reveals Onchain Addresses Linked to 4 Major Bitcoin ETFs, Boosting Market Transparency - On Jan. 23, Arkham, a firm specializing in onchain intelligence, announced the ide... - https://news.bitcoin.com/arkham-reveals-onchain-addresses-linked-to-4-major-bitcoin-etfs-boosting-market-transparency/ #franklintempleton #bitcoinreserves #cryptocurrency #blackrock #fidelity #bitwise #crypto #news #bitb #ezbc #fbtc #ibit #btc
-
Arkham Reveals Onchain Addresses Linked to 4 Major Bitcoin ETFs, Boosting Market Transparency - On Jan. 23, Arkham, a firm specializing in onchain intelligence, announced the ide... - https://news.bitcoin.com/arkham-reveals-onchain-addresses-linked-to-4-major-bitcoin-etfs-boosting-market-transparency/ #franklintempleton #bitcoinreserves #cryptocurrency #blackrock #fidelity #bitwise #crypto #news #bitb #ezbc #fbtc #ibit #btc
-
Ein Sicherheitsforscher stellt einen erweiterten Phishing-Ansatz zum Einkassieren von Passwörtern vor. Betrüger sollten jetzt aufhören zu lesen.
Doppelter Betrug: Phishing-Konzept mit Browser-In-The-Browser-Attacke ausgebaut -
#Browser in the Browser (#BITB) #Attack
Source
https://mrd0x.com/browser-in-the-browser-phishing-attack/