Blog · Phishing · 9 October 2026 · 3 min read
A fake Microsoft login window you can't spot by eye: how Browser-in-the-Browser works
In September 2026 researchers described a campaign that leads through DocuSign and Adobe to a perfectly forged Microsoft 365 login window. One simple test exposes it.
You get an e-mail: "Document to sign in DocuSign". The sender looks like someone from your company, it uses your name, and there's one button. You click, pass an "I'm not a robot" check, see a document in Adobe Acrobat, and above it a message: to open it, sign in with your Microsoft account. A login window pops up, with login.microsoftonline.com in the address bar and a padlock.
That window isn't real. It's Browser-in-the-Browser (BitB): a picture of a browser window drawn inside the attacker's page.
What changed in 2026
The BitB technique has been around for years, but in 2026 it became one step in longer, convincing chains:
- June 2026: Unit 42 (Palo Alto Networks) described a campaign with fake Microsoft 365 login windows that you can drag with the mouse and that adapt their look to the victim's system.
- 8 September 2026: Barracuda described the chain DocuSign → CAPTCHA check → "Adobe Acrobat" window → fake Microsoft login. The CAPTCHA isn't there for you: it keeps automated e-mail scanners from reaching the trap page.
- 9–10 September 2026: a variant was also described where the fake page is built only inside your browser (a
blob:address), with redirects running through genuine Microsoft and Teams infrastructure. Filters that check page addresses see nothing.
The test that always works: drag the window
A real login window is a separate browser window. A fake one is part of the page.
- Grab the window by its title bar and drag it outside the browser window. A real one moves out. A fake one stops at the edge or disappears.
- Look at the real address bar, the one at the very top of the browser, not the one in the pop-up. The address in the pop-up is just text on the page.
- Minimise the browser or switch tabs. A real login window stays separately on the taskbar.
The simplest rule: if a document asks you to sign in, close the e-mail and sign in yourself by typing office.com or opening the Outlook or Teams app.
What to set up in your company
- Hardware keys or passkeys (FIDO2) instead of SMS codes. They work only on Microsoft's real domain, so even if someone types a password into a fake window, the key won't work.
- Stop staff from approving apps on their own in Microsoft 365 (OAuth consent). Some of these campaigns don't steal the password; they ask for "app access" to the mailbox.
- DMARC, SPF and DKIM on your own domain. They make it harder to impersonate your company.
- After any suspicious click: change the password, sign out all Microsoft 365 sessions and check the mailbox forwarding rules.
In short
- A login window opened from a document is suspicious by definition.
- Drag the window outside the browser. If it won't leave, it's fake.
- Sign in yourself, from a bookmark or the app, never from a link in an e-mail.
- A FIDO2 key or passkey stops this attack even when a person makes a mistake.
Sources: Barracuda, 8 Sep 2026, Help Net Security, 10 Sep 2026, Help Net Security, 10 Jun 2026.