HawerGroup

Blog · Phishing · 9 October 2026 · 3 min read

A fake Microsoft login window you can't spot by eye: how Browser-in-the-Browser works

In September 2026 researchers described a campaign that leads through DocuSign and Adobe to a perfectly forged Microsoft 365 login window. One simple test exposes it.

You get an e-mail: "Document to sign in DocuSign". The sender looks like someone from your company, it uses your name, and there's one button. You click, pass an "I'm not a robot" check, see a document in Adobe Acrobat, and above it a message: to open it, sign in with your Microsoft account. A login window pops up, with login.microsoftonline.com in the address bar and a padlock.

That window isn't real. It's Browser-in-the-Browser (BitB): a picture of a browser window drawn inside the attacker's page.

What changed in 2026

The BitB technique has been around for years, but in 2026 it became one step in longer, convincing chains:

  • June 2026: Unit 42 (Palo Alto Networks) described a campaign with fake Microsoft 365 login windows that you can drag with the mouse and that adapt their look to the victim's system.
  • 8 September 2026: Barracuda described the chain DocuSign → CAPTCHA check → "Adobe Acrobat" window → fake Microsoft login. The CAPTCHA isn't there for you: it keeps automated e-mail scanners from reaching the trap page.
  • 9–10 September 2026: a variant was also described where the fake page is built only inside your browser (a blob: address), with redirects running through genuine Microsoft and Teams infrastructure. Filters that check page addresses see nothing.

The test that always works: drag the window

A real login window is a separate browser window. A fake one is part of the page.

  1. Grab the window by its title bar and drag it outside the browser window. A real one moves out. A fake one stops at the edge or disappears.
  2. Look at the real address bar, the one at the very top of the browser, not the one in the pop-up. The address in the pop-up is just text on the page.
  3. Minimise the browser or switch tabs. A real login window stays separately on the taskbar.

The simplest rule: if a document asks you to sign in, close the e-mail and sign in yourself by typing office.com or opening the Outlook or Teams app.

What to set up in your company

  • Hardware keys or passkeys (FIDO2) instead of SMS codes. They work only on Microsoft's real domain, so even if someone types a password into a fake window, the key won't work.
  • Stop staff from approving apps on their own in Microsoft 365 (OAuth consent). Some of these campaigns don't steal the password; they ask for "app access" to the mailbox.
  • DMARC, SPF and DKIM on your own domain. They make it harder to impersonate your company.
  • After any suspicious click: change the password, sign out all Microsoft 365 sessions and check the mailbox forwarding rules.

In short

  • A login window opened from a document is suspicious by definition.
  • Drag the window outside the browser. If it won't leave, it's fake.
  • Sign in yourself, from a bookmark or the app, never from a link in an e-mail.
  • A FIDO2 key or passkey stops this attack even when a person makes a mistake.

Sources: Barracuda, 8 Sep 2026, Help Net Security, 10 Sep 2026, Help Net Security, 10 Jun 2026.