Cyber Security News

New Phishing Attack Using Browser-In-The-Browser Technique To Attack Gamers

A sophisticated new phishing campaign has emerged targeting the gaming community, specifically Counter-Strike 2 players, using an advanced technique known as Browser-in-the-Browser (BitB).

This attack method creates a convincing fake browser pop-up window that tricks users into entering their Steam credentials, allowing cybercriminals to steal valuable gaming accounts and virtual items.

The campaign primarily targets fans of professional esports team Navi (Natus Vincere), luring victims with promises of free in-game items, skins, and cases.

caseneus[.]cfd (Source – Silent Push)

Attackers have established multiple phishing domains with names suggesting connections to the popular team, including variations like “caseneos[.]cfd” and “caserevs[.]com”.

These sites are promoted through social media and YouTube videos promising free Counter-Strike 2 skins.

Silent Push researchers noted this attack in March 2025, noting that the phishing operation appears to originate from Chinese threat actors, with some sites displaying content in Mandarin alongside English elements.

The researchers observed hundreds of similar domains using identical templates, suggesting a large-scale, coordinated campaign.

The Browser-in-the-Browser technique represents a particularly deceptive form of phishing.

Unlike traditional phishing that simply mimics website designs, BitB creates a fake browser window within the victim’s legitimate browser.

A BitB attack on caseneos[.]com shows a fake browser pop-up with a clickable URL bar (Source – Silent Push)

This includes spoofing browser UI elements like the address bar, security padlock icon, and window controls.

When users click on what appears to be a Steam login button, they’re presented with this fake browser window displaying a convincing replica of the Steam login page.

A website selling Steam accounts with pricing (Source – Silent Push)

Technical Analysis of the BitB Implementation

The technical sophistication of this attack lies in its visual deception.

The fake browser window is actually constructed using HTML and CSS to precisely mimic browser chrome elements.

When examining the attack closely, users would notice the URL in the fake address bar cannot be selected or modified, as it’s merely part of an image or styled HTML elements.

Furthermore, interactions with browser-specific features like bookmarks or extensions fail to produce expected results.

The attackers have implemented multiple detection evasion techniques, including domain rotation, with new phishing domains being registered almost daily.

Silent Push’s analysis revealed a dedicated IP address (77.105.161[.]50) hosting numerous phishing domains with identical HTML structure.

To protect against such attacks, gamers should verify URL authenticity by attempting to edit the address bar, check for HTTPS padlock functionality, and use Steam’s mobile app for QR code authentication rather than entering credentials directly into browser windows.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago