CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6925

As cited

Copy frozen at (site build).

threat intel

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Huntress observed phishing attacks delivering browser-in-the-browser pages to deceive users into accessing credential harvesting sites. Attackers established persistence through rogue ScreenConnect installations, a remote monitoring and management tool, to maintain access and evade detection.

Why it matters: Organizations face credential compromise and unauthorized remote access from these phishing campaigns; security teams should monitor for suspicious ScreenConnect deployments and educate users on browser-in-the-browser deception tactics.

VendorsConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary