Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress, Wednesday, September 9th, 2026
Browser-in-the-browser phishing led to rogue ScreenConnect persistence in incidents Huntress analysts unpicked.
Huntress analysts detail incidents where browser-in-the-browser phishing, which renders a convincing fake browser window inside a real page, led to credential theft and then rogue ScreenConnect installation for persistence.
The technique defeats the standard user advice to check the address bar, because the address bar the victim examines is drawn by the attacker's page.
The write-up covers the evasion tactics observed and the artifacts that revealed the activity, which is directly useful for analysts building detections around remote management tool installation.