Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

116257

Fake Microsoft 365 Login Windows Turn User Trust Into a Phishing Risk

Overview

A new Browser-in-the-Browser phishing technique is targeting Microsoft 365 users with a fake login window that closely imitates a legitimate Microsoft authentication popup. Instead of opening a real browser window, the attack renders a convincing fake window inside the malicious webpage itself. The victim sees familiar branding, a realistic-looking address bar, and a lock icon, but the credentials are entered into an attacker-controlled environment.

This technique is dangerous because it targets the way users visually assess whether a login prompt is legitimate. In Microsoft 365 environments, the risk is especially serious because successful compromise may expose email, files, Teams, OneDrive, and connected cloud services.

How the Attack Works

The attack begins when a user lands on a page that appears to require Microsoft authentication. After clicking a “Sign in with Microsoft” button, the page displays a fake login popup. The window is not a real browser popup. It is built inside the active page using HTML, CSS, and JavaScript.

To make the deception more convincing, the fake window may be draggable, include a spoofed address bar, and adapt its appearance to the victim’s operating system and browser. This removes some of the visual cues users normally rely on to identify suspicious login prompts.

Once credentials are entered, they are sent to attacker-controlled infrastructure. In many cases, the victim may then be redirected to the real Microsoft login page, making the failed first attempt appear harmless.

Why This Matters

Browser-in-the-Browser phishing reflects a broader shift in phishing operations. Attackers are no longer relying only on obvious fake pages or suspicious domains. They are building highly convincing user experiences that mimic trusted platform behavior.

In Microsoft 365 environments, one compromised account may give attackers access to:

  • corporate email
  • OneDrive and SharePoint files
  • Teams communication
  • internal documents
  • calendars and contacts
  • other cloud applications connected to the account

OAuth and active session abuse adds another layer of risk. Microsoft has already warned about campaigns abusing legitimate OAuth redirection mechanisms, while the FBI warned in May 2026 about phishing-as-a-service platforms targeting Microsoft 365 OAuth tokens.

Potential Impact

If the attack succeeds, the attacker may obtain credentials or tokens that enable ongoing access to the account. This matters because changing the password may not always be enough if an active session or valid access token remains available.

Potential impact includes:

  • Microsoft 365 account takeover
  • reading and sending emails as the victim
  • access to files and internal documents
  • theft of contacts and calendar data
  • follow-on phishing from a legitimate account
  • expansion of access to other users and services

This makes the attack relevant not only to awareness training, but also to identity and session management.

Recommended Actions

Organizations should combine technical controls, user awareness, and identity monitoring.

Priority actions include:

  • use phishing-resistant authentication such as passkeys or FIDO2 security keys
  • enforce Conditional Access policies
  • monitor sign-ins from unfamiliar devices, locations, and browsers
  • review and revoke suspicious OAuth grants
  • terminate active sessions when compromise is suspected
  • use password managers, as they typically will not autofill credentials into fake windows from the wrong origin
  • train users to recognize fake login windows, especially when the prompt appears inside a webpage rather than as a real browser window

Microsoft recommends managing OAuth consent carefully and reducing consent phishing risk through app consent policies and monitoring.

DIAMATIX Perspective

This attack shows why phishing defense can no longer rely only on detecting suspicious emails or domains. Attackers are targeting user trust in familiar interfaces.

The core risk comes from the combination of:

  • visually convincing deception
  • Microsoft 365 as a widely used enterprise environment
  • possible theft of active sessions or OAuth access
  • difficulty distinguishing real and fake login windows
  • potential persistence after the initial phishing event

Protection must cover the full session lifecycle: sign-in, tokens, devices, location, app permissions, and post-authentication behavior.

CISO Analysis

From a CISO perspective, this is an identity security issue, not only a phishing event.

Key questions include:

  • Can we detect Microsoft 365 sign-ins from unusual devices and locations?
  • Are OAuth app permissions monitored?
  • Do we have a process to revoke tokens and terminate active sessions?
  • Are critical roles protected with phishing-resistant MFA?
  • Can we distinguish normal user behavior from compromised session behavior?
  • Is access restricted to managed and compliant devices?

MFA helps, but it is not sufficient if users are tricked into approving a legitimate-looking flow or if attackers obtain a valid token. Identity protection must include post-login monitoring, not only authentication checks.

What This Means for Your Environment

  • This type of attack relies on visual deception and abuse of trust in the Microsoft 365 login process, not only a traditional fake login page.
  • Detection depends on visibility into sign-ins, active sessions, OAuth permissions, and post-authentication behavior.
  • Response requires revoking suspicious tokens, terminating sessions, reviewing accounts, and strengthening identity controls.

Could you detect a compromised Microsoft 365 session if the password was never changed?

Do you have visibility into OAuth grants and active sessions across your environment?

See how identity-focused phishing attacks are investigated and handled in real operational environments.

Contact DIAMATIX
Trusted · Innovative · Vigilant


Sources

  • Unit 42 / public reporting on the Browser-in-the-Browser phishing campaign.
  • Microsoft. OAuth redirection abuse and OAuth consent phishing guidance.
  • FBI IC3. Kali365 phishing-as-a-service warning.
  • Cyber Security News. Browser-in-the-Browser campaign targeting Microsoft 365.

This article is based on publicly available technical information and analysis as of June 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.