Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsHuntress

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Huntress, Wednesday, September 9th, 2026

Browser-in-the-browser phishing led to rogue ScreenConnect persistence in incidents Huntress analysts unpicked.

Huntress analysts detail incidents where browser-in-the-browser phishing, which renders a convincing fake browser window inside a real page, led to credential theft and then rogue ScreenConnect installation for persistence.

The technique defeats the standard user advice to check the address bar, because the address bar the victim examines is drawn by the attacker's page.

The write-up covers the evasion tactics observed and the artifacts that revealed the activity, which is directly useful for analysts building detections around remote management tool installation.

more →  ·  More from Huntress →