Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense · Medium sophistication
Last updated August 26, 2026

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run commands/install tools that give attackers access. The techniques highlighted include fake software installs/updates, Browser-in-the-Browser (BitB) login fakes, ClickFix “verification” pages, and Microsoft device-code phishing.

Key findings

  • Attackers are shifting from exploiting browser software flaws to exploiting employee trust in normal browser workflows (logins, updates, verification checks).
  • Observed campaigns imitate common, trusted experiences: software updates/installers, single sign-on popups, CAPTCHA/verification steps, and legitimate Microsoft device sign-in flows.
  • Some campaigns aim to steal credentials (BitB), while others aim to get users to install remote access tools (RATs) or run commands (ClickFix).
  • Because activity can happen inside legitimate-looking browser interactions (including legitimate Microsoft pages for device code phishing), traditional controls may miss it.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk / support, Identity & access management (IAM) teams, Security operations (SOC).
  • Affected industries: Cross-industry (general enterprise users of cloud apps and browsers).
  • Attack channels: website, email.
  • Impersonated: Adobe Reader / PDF document viewer, Website security verification / CAPTCHA page, Microsoft device sign-in flow (legitimate Microsoft portal, attacker-provided code).

Awareness takeaways

  • Treat unexpected ‘update required to view this document’ prompts as suspicious and only install software via approved company channels.
  • Never run PowerShell/Terminal/Run commands because a webpage or CAPTCHA tells you to, report it as a likely scam.
  • Device-code sign-ins can be abused: don’t enter device codes you didn’t request, even if the page is a legitimate Microsoft site.
  • Be cautious of login pop-ups embedded inside webpages; attackers can fake ‘normal’ sign-in windows to steal passwords.

Red flags to watch for

  • Unexpected update requirement to view a document
  • Update/install prompt appears after clicking a link rather than from official IT/software management
  • Pressure to install software immediately to continue
  • A CAPTCHA/verification page telling you to run PowerShell or system commands
  • Instructions to use Windows Run/Terminal for a web verification step
  • Unusual multi-step “fix” instructions unrelated to normal browsing
  • Unsolicited request to use a device code to sign in
  • You are asked to enter a code you didn’t generate/request
  • Sign-in completes but you didn’t initiate a new device/app login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Your browser can lie to you now. Not by bugs, by perfect fakes of updates, CAPTCHAs, and login pop-ups. Example one: a PDF link says, “This document can’t be viewed, update the viewer.” The page spoofs Adobe Reader and walks you through an install, really it’s dropping a remote access tool. Example two: a CAPTCHA says, “Verification required,” then tells you to copy PowerShell commands to fix your browser. Here’s the twist: some scams don’t fake the page at all. They use real Microsoft device sign-in, but with a code they give you. Others use “browser-in-the-browser” pop-ups that look like normal single sign-on windows, floating inside the webpage to steal your password. Aha rule: if a webpage tells you to install software or run PowerShell, Terminal, or Run commands, stop and report it to IT, do not follow the steps.

Categories

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Teams HR Phish Used Real Microsoft Login Flow

Teams HR Phish Used Real Microsoft Login Flow

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook,…

July 30, 2026
ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026