Press start >>

Push Logo

Browser attacks glossary

What are browser attacks?

Adversary-in-the-Middle (AiTM)

Also known as: MFA bypass phishing / reverse proxy phishing / session phishing / transparent proxy phishing

Adversary-in-the-Middle (AiTM) is a type of phishing attack that uses a reverse proxy to sit between the victim and a legitimate login page, relaying credentials and session tokens in real time. Bypasses MFA because the attacker captures the authenticated session cookie, not just the password.

Browser & Identity Attacks Matrix

Adware / Potentially Unwanted Programs (PUPs)

Adware and potentially unwanted programs (PUPs) inject ads into the browser, change the homepage or default search engine, or install toolbars without meaningful consent. Distributed through bundled software installers, deceptive download buttons, and rogue browser extensions. Historically associated with browser toolbars; now more commonly delivered via extensions. Overlaps with browser hijacking.

AI-generated phishing

AI-generated phishing uses AI to generate elements of the lure, page, infrastructure, and so on. AI eliminates the grammatical errors and formatting inconsistencies that traditional phishing awareness training teaches users to spot. AI can also be used to generate and serve tailored, rotating lures and infrastructure to victims to evade detection and improve success rates.

App-specific password phishing

Also known as: ASP phishing / application password phishing

App-specific password phishing is a phishing attack that targets app-specific passwords — legacy credentials that some services (Google, Microsoft, Yahoo) allow users to generate for apps that don't support modern authentication. These passwords bypass MFA entirely because they're designed for clients that can't handle interactive sign-in flows. Attackers phish users for these passwords or trick them into generating one, gaining persistent access that isn't protected by MFA and often isn't visible in normal sign-in logs.

Browser & Identity Attacks Matrix

Authorization phishing

Also known as: authorization-based phishing / auth flow abuse

Authorization phishing is an umbrella term for phishing attacks that target authorization flows rather than credentials — tricking users into granting access instead of revealing passwords. Covers OAuth consent phishing, device code phishing, and ConsentFix-style prompts. Because the user authorizes the attacker through a legitimate flow, no credentials are stolen and MFA is never challenged.

Browser extension supply chain attacks

Browser extension supply chain attacks compromise legitimate browser extensions to inject malicious code that affects all existing users. An attacker gains access to the extension developer's account or build pipeline, pushes a malicious update, and the compromised version auto-deploys to every user of that extension.

Browser hijacking

Browser hijacking is the modification of browser settings (homepage, default search engine, new tab page) without user consent. Achieved via malicious extensions, bundled software, or registry/config changes. Historically toolbar-based; modern variants are extension-based. Not a distinct attack — it's the outcome of adware, PUPs, or malicious extensions.

Browser notification spam

Browser notification spam is the abuse of the Web Push Notifications API to deliver scam alerts, fake virus warnings, and phishing links directly to a user's desktop or mobile device. The attack starts when a user grants notification permission — often via a deceptive "click Allow to continue" prompt. Once granted, attackers can push notifications at will. A delivery vector for malicious downloads and ClickFix-style social engineering.

Browser-in-the-Browser (BitB)

Browser-in-the-Browser (BitB) is a phishing technique that uses HTML, CSS, and JavaScript to render a fake browser pop-up window — complete with a spoofed address bar, padlock icon, and SSO branding — inside a real web page. Targets "Sign in with Google/Microsoft/Apple" flows. Same underlying attack as AiTM phishing with additional UI trickery to make the fake login window more convincing.

Browser & Identity Attacks Matrix

Callback phishing

Also known as: TOAD (telephone-oriented attack delivery) / hybrid vishing

Callback phishing is a phishing attack with no malicious link or attachment — instead, the email contains a phone number and a pretext (fake invoice, subscription renewal, security alert) designed to get the victim to call. Once on the phone, the attacker walks the victim through actions in their browser: visiting a malicious site, downloading remote access software, or entering credentials on a phishing page.

Browser & Identity Attacks Matrix

ClickFix (+Fix variants)

Also known as: FakeFix / ClearFix / fake CAPTCHA / paste-and-run attacks

ClickFix is a social engineering attack that tricks users into copying and executing malicious commands by presenting a fake error message with "fix" instructions. These commands typically result in the deployment of infostealer malware and remote access tooling. ClickFix lures and sub-techniques are hugely varied as a result of high levels of attacker investment in new tools and methods.

Browser & Identity Attacks Matrix

Clickjacking

Also known as: UI redress attack / likejacking

Clickjacking is an attack that tricks users into clicking something different from what they perceive, typically by overlaying a transparent iframe over a legitimate page element. The user believes they're clicking a visible button but actually triggers an action on a hidden page underneath. A delivery vector — used to trigger consent grants, initiate downloads, or perform actions on another site without the user's knowledge.

Browser & Identity Attacks Matrix

Clipboard hijacking / pastejacking

Clipboard hijacking (or pastejacking) swaps what a user copied for content the attacker chose. The name is shared by two distinct attack patterns. In the ClickFix context, attackers use JavaScript to overwrite clipboard contents so that when users paste into a terminal, they execute malicious commands instead of what they copied. In the crypto context, malware monitors the clipboard for wallet addresses and silently swaps them with attacker-controlled addresses.

CloudFix

CloudFix is a ClickFix variant that impersonates cloud service error messages (e.g. OneDrive, Google Drive, Dropbox) to trick users into executing malicious commands. Same underlying technique as ClickFix — fake error, clipboard hijack, PowerShell execution — with cloud-themed lures.

Compromised websites

Compromised websites are legitimate websites that have been injected with malicious code — through vulnerabilities in the CMS (typically WordPress), compromised admin credentials, or supply chain attacks on third-party scripts and plugins. Visitors encounter drive-by downloads, fake browser update prompts, injected redirect chains, cryptomining scripts, or SEO spam. The site looks and behaves normally except for the injected payload, so users have no reason to distrust it. Watering hole attacks are a targeted subset where attackers deliberately compromise sites frequented by a specific organization or industry.

CrashFix

CrashFix is a ClickFix variant that mimics application crash reports or system error dialogs. The user is prompted to run a "diagnostic" or "repair" command that executes malicious code.

Credential phishing

Also known as: login page phishing / credential harvesting / password phishing

Credential phishing is a phishing attack specifically designed to steal usernames and passwords by presenting a fake login page that mimics a legitimate service. The most common form of phishing — the attacker clones a login page, hosts it on a lookalike or compromised domain, and directs victims to it via email, IM, or other channels. Modern credential phishing often uses AiTM reverse proxies to capture session tokens alongside credentials, bypassing MFA.

Credential stuffing

Also known as: credential reuse attacks / breach replay

Credential stuffing is an automated attack that tests stolen username/password pairs (from data breaches) against multiple login pages. Exploits password reuse. Distinct from brute force (which guesses passwords) and password spraying (which tests common passwords across many accounts).

Browser & Identity Attacks Matrix

Cross-IdP impersonation

Also known as: identity provider impersonation / federation impersonation

Cross-IdP impersonation is an attack where a threat actor exploits trust relationships between identity providers to impersonate users across federated environments. The attacker compromises or creates an account in one IdP and leverages federation trust to gain access to resources in another IdP's domain. Exploits the implicit trust that federated environments place in assertions from partner identity providers.

Browser & Identity Attacks Matrix

Deepfake video/voice scams

Deepfake video and voice scams use AI-generated video and voice cloning in real-time calls to impersonate executives and authorize fraudulent transactions. Attackers clone voices from short audio samples and generate synthetic video that matches lip movements to speech in real time. The calls increasingly happen through browser-based meeting platforms. Often used as a lure to deliver browser-based payloads like phishing and ClickFix.

Device code phishing

Also known as: device authorization grant abuse / device flow phishing

Device code phishing is a phishing technique that abuses OAuth 2.0 device authorization flows. The attacker initiates a device code request and tricks the victim into entering the code on a legitimate Microsoft (or other IdP) login page. Because the victim authenticates on the real IdP domain, MFA and passkeys don't help — the attacker receives the resulting tokens. Distinct from AiTM (no proxy involved) and consent phishing (abuses device flow, not app consent).

Browser & Identity Attacks Matrix

DNS hijacking / DNS spoofing

DNS hijacking (or DNS spoofing) is the manipulation of DNS resolution to redirect users from legitimate sites to attacker-controlled destinations. Methods include compromising DNS servers, poisoning DNS caches, modifying router DNS settings, or intercepting DNS queries. The browser shows the correct URL in the address bar, making the redirect invisible to users. Often used with phishing pages or credential harvesting.

Drive-by downloads

Drive-by downloads deliver malware when a user visits a compromised or malicious website. Classic drive-bys exploited browser or plugin vulnerabilities to download silently without any user interaction, but modern browser sandboxing has made truly zero-interaction exploits rare. Most contemporary variants require minimal interaction — clicking a fake update prompt, approving a download, or running an installer. Often delivered through malvertising, compromised legitimate sites, or exploit kits.

Email phishing

Email phishing is a phishing attack delivered via email — the most common initial access vector. Includes credential harvesting pages linked from spoofed emails, business email compromise (BEC), and spear phishing targeting specific individuals. Increasingly enhanced by AI-generated content that eliminates traditional tell-tale signs like grammatical errors.

Browser & Identity Attacks Matrix

Evil twin Wi-Fi

Evil twin Wi-Fi attacks use a rogue Wi-Fi access point that impersonates a legitimate network (same SSID, sometimes same password). The credential theft happens in the browser: modern attacks deploy a captive portal that mimics a familiar login screen, and the victim enters credentials thinking they're authenticating to the network. Can also intercept unencrypted traffic or man-in-the-middle browser sessions.

Fake browser updates

A fake browser update is a social engineering attack that injects a "your browser is out of date" banner into compromised legitimate websites. Users who click the "update" button download malware instead. Often serves as an initial access vector for ransomware.

Formjacking / web skimming (Magecart)

Also known as: card skimming / digital skimming / e-skimming

Formjacking, or web skimming, uses malicious JavaScript injected into payment pages of e-commerce sites to capture credit card details as customers type them. Operates in real time within the browser, making it invisible to server-side security. A specific payload type found on compromised websites.

Ghost logins

Also known as: shadow access / SSO bypass / orphaned accounts

Ghost logins are hidden login paths that persist after SSO access is revoked — local accounts, saved passwords, or direct-URL logins that bypass the IdP entirely. Attackers (or former employees) can access SaaS apps long after their SSO session is terminated because the underlying local account was never deactivated.

Browser & Identity Attacks Matrix

Help desk phishing / social engineering

Help desk phishing (or help desk social engineering) is an attack where a threat actor contacts an organization's IT help desk impersonating an employee to reset credentials, enroll a new MFA device, or gain access to accounts. The attacker typically has enough personal information to pass identity verification. Once they have a fresh password or MFA token, the actual compromise happens in the browser — logging into the victim's SaaS apps, email, or VPN portal.

Homograph / homoglyph attacks (IDN spoofing)

Homograph (or homoglyph) attacks are a domain spoofing technique that uses characters from non-Latin alphabets (typically Cyrillic) that are visually identical to Latin characters. The domain looks legitimate in the address bar but resolves to an attacker-controlled server, often with a valid SSL certificate and padlock icon. Unlike typosquatting, there is nothing visually wrong for a human to catch.

IM phishing (Slack, Teams, WhatsApp)

IM phishing is a phishing attack delivered through instant messaging platforms via direct messages, group channels, or external guest access. Often more effective than email phishing because users trust messages from colleagues and the informal context lowers suspicion. Platforms with external messaging or guest access features are particularly exposed.

Browser & Identity Attacks Matrix

In-app phishing

In-app phishing is a phishing attack delivered through legitimate SaaS application features — issue comments, tickets, document sharing notifications, calendar invites, and similar. Attackers abuse native collaboration features to deliver malicious links from within trusted platforms. The phishing link may still arrive by email, but the email itself is legitimate — sent from the app's real domain — so it passes reputation and authentication checks.

Browser & Identity Attacks Matrix

Infostealers

Also known as: stealer malware / credential stealers / info-stealing trojans

Infostealers are malware designed to extract credentials, session cookies, browser autofill data, and cryptocurrency wallets from infected devices. Delivered via phishing, malvertising, fake software downloads, and trojanized installers. The stolen data (known as "logs") is sold on dark web marketplaces and used for account takeover, session hijacking, and credential stuffing at scale. ClickFix is the most common delivery method for infostealer malware today, followed by malicious file downloads.

Malicious browser extensions

Malicious browser extensions are browser extensions that steal data, inject ads, hijack search results, or provide backdoor access. Includes supply chain attacks where legitimate extensions are compromised via the developer's account or build pipeline. Extensions have broad permissions — they can read all page content, modify requests, and access cookies across every site the user visits.

Malicious file downloads

Malicious file downloads are files downloaded through the browser that carry malware, such as drive-by downloads and trojanized software installers. Includes file types commonly used for malware delivery (.exe, .msi, .iso, .js, .vbs, .ps1, .hta).

Malicious OAuth integrations

Also known as: OAuth abuse / SaaS supply chain attack / third-party integration compromise

Malicious OAuth integration attacks are supply chain attacks that exploit the web of OAuth integrations connecting third-party apps to your core SaaS environment. Rather than phishing your users directly, attackers compromise a vendor your organization already trusts — then use its existing OAuth grants to read mail, exfiltrate files, and pivot into connected tenants. Because access rides on legitimate, previously-approved tokens, there is no login event to detect, MFA is never challenged, and the access survives password resets. Related patterns include evil twin integrations, nOAuth account takeover, and OAuth token enumeration.

Malvertising

Also known as: malicious search results / sponsored search phishing

Malvertising is malicious content delivered through paid advertising networks, including sponsored search results and display ads on legitimate, high-traffic websites. Attacks range from forced redirects to exploit kit delivery to fake download pages.

Man-in-the-Browser (MitB)

Man-in-the-Browser (MitB) is an attack in which a trojan hooks into the browser process and manipulates web transactions in real time — historically used for banking fraud, where the malware silently altered transfer details while showing the user the original values. It is a consequence of endpoint malware rather than a browser-native attack. MFA doesn't help because the malware operates on the already-authenticated session. Largely superseded by infostealers (which exfiltrate credentials and cookies in bulk) and malicious browser extensions (which achieve similar in-browser manipulation through the extension API).

Browser & Identity Attacks Matrix

MFA bypass

MFA bypass is an umbrella term for techniques that get an attacker past multi-factor authentication without defeating the factor itself — proxying the login in real time (AiTM), forcing a fallback to a weaker factor (MFA downgrade), bombarding the user with push prompts (MFA fatigue), or skipping authentication entirely by stealing the post-MFA session. MFA raises the bar, but modern phishing kits are built to clear it.

Browser & Identity Attacks Matrix

MFA downgrade

Also known as: authentication downgrade / step-down attack

MFA downgrade is an attack that forces a user's authentication to fall back from a stronger MFA method to a weaker one — for example, from FIDO2/passkey to SMS OTP or email verification. Attackers exploit IdP configurations that allow fallback methods, or manipulate the authentication flow to trigger a downgrade. Once downgraded to a weaker factor, the attacker can intercept or social-engineer the code. In practice this is an extension of AiTM rather than a distinct attack — AiTM phishing kits manipulate the proxied login flow to trigger the fallback, then capture the weaker factor in transit.

Browser & Identity Attacks Matrix

MFA fatigue / push bombing

MFA fatigue (or push bombing) is an attack where the attacker repeatedly triggers MFA push notifications to a victim's phone, hoping they'll approve one out of frustration or confusion — often late at night or during busy periods. Largely mitigated by number matching and phishing-resistant MFA (FIDO2/passkeys), but still effective against organizations using simple push-approve MFA.

Browser & Identity Attacks Matrix

Mobile phishing (QR & SMS)

Mobile phishing is a phishing attack delivered via QR codes (quishing) or SMS messages (smishing) rather than email. Bypasses email security entirely because the phishing link never passes through the email gateway. QR codes are particularly effective because they force the user onto a mobile device where URL inspection is harder and security tooling is typically weaker.

Browser & Identity Attacks Matrix

Password spraying

Password spraying is an attack that tests a small number of commonly used passwords against a large number of accounts. Distinct from credential stuffing (which uses known leaked password pairs) and brute force (which tries many passwords against one account). Designed to stay below account lockout thresholds. Often the first step before more targeted attacks.

Browser & Identity Attacks Matrix

Phishing

Phishing is an umbrella term for attacks that trick users into revealing credentials, approving access, or taking harmful actions by impersonating a trusted entity. Modern phishing extends far beyond email — attackers deliver it through IM platforms, social media, in-app notifications, QR codes, SMS, voice calls, and search engine ads. The common thread: the credential theft or action happens in the browser, regardless of the delivery channel.

QR code phishing (quishing)

QR code phishing (quishing) uses QR codes embedded in emails, documents, or physical media to direct victims to phishing pages. Bypasses email link scanning because the URL is encoded in the image, not in a clickable link.

SaaS supply chain attacks

Also known as: third-party app compromise / vendor compromise

SaaS supply chain attacks compromise a third-party SaaS vendor and use it as a stepping stone into its customers' environments. The attacker breaches the vendor, then abuses the OAuth grants and API tokens its customers have already approved to access their data — no phishing, no login, no MFA prompt in the victim tenant. High-profile incidents targeting integrations connected to Salesforce, Snowflake, and Microsoft 365 follow this pattern.

SAMLjacking

Also known as: SAML hijacking / federation hijacking

SAMLjacking is an attack where a threat actor with admin access to an identity provider configures SAML federation to redirect authentication flows through an attacker-controlled IdP. This gives the attacker the ability to authenticate as any user in the federated environment without knowing their credentials. Can also be used for lateral movement — once an attacker compromises one IdP, they can pivot into downstream apps that trust SAML assertions from that provider.

Browser & Identity Attacks Matrix

Scareware / tech support scams

Scareware and tech support scams use full-screen browser alerts that claim the user's device is infected, displaying a phone number for fake "tech support." The alerts use browser APIs (fullscreen requests, beforeunload handlers, repeated dialog prompts) to make the tab feel unclosable. A delivery vector — leads to either malicious software downloads or voice-based social engineering when victims call the displayed number.

SEO poisoning

Also known as: search engine poisoning

SEO poisoning is the manipulation of organic search engine rankings to surface malicious pages for targeted queries. Attackers optimize pages for keywords enterprise employees are likely to search — VPN clients, software downloads, IT documentation — and serve phishing pages, malware downloads, or credential traps.

Session hijacking

Also known as: session theft / token replay / cookie theft / session token hijacking

Session hijacking is the theft and replay of authenticated session tokens to access accounts without credentials. Tokens are stolen via infostealers, XSS, man-in-the-browser malware, or network interception. Because the attacker uses a valid session token, MFA doesn't help — the authentication already happened.

Browser & Identity Attacks Matrix

Social media phishing (LinkedIn, Facebook, X)

Social media phishing is a phishing attack delivered through social media platforms — connection requests, direct messages, fake job offers, and sponsored posts containing malicious links. LinkedIn is heavily targeted for business-focused attacks (fake recruiter outreach, impersonated executives). Attackers create convincing profiles with stolen photos and fabricated work histories, or compromise legitimate accounts as a means to engage with their existing connections from a trusted point of contact.

Browser & Identity Attacks Matrix

Tabnabbing

Tabnabbing is a phishing technique that exploits inactive browser tabs. A malicious page detects when the user switches away, then silently changes its favicon, title, and content to mimic a login page. When the user returns, they see what looks like a session timeout and re-enter credentials.

Typosquatting

Typosquatting is the registration of domains that are common misspellings of legitimate sites (e.g. gooogle.com, microsoftt.com). Users who mistype a URL land on an attacker-controlled page serving phishing forms, malware downloads, or scam content. Attackers obtain valid SSL certificates for these domains, so the padlock icon provides no protection. Related to but distinct from homograph attacks.

Verification phishing

Also known as: email verification phishing / verification code phishing

Verification phishing is an attack where an adversary uses social engineering to convince a user to click an email verification link or share a verification code on the attacker's behalf. Email verification is commonly used as a control when registering new accounts — the attacker needs the target to complete this step to bypass it. Most relevant when combined with cross-IdP impersonation, where the attacker circumvents strong SSO authentication to gain direct control of downstream SaaS applications.

Vishing (voice phishing)

Vishing (voice phishing) is phishing conducted over phone calls rather than email. The attacker impersonates IT support, a bank, a vendor, or a colleague and directs the victim to take actions in their browser — visiting a phishing page, downloading remote access software, entering credentials, or approving an MFA prompt. Increasingly uses AI voice cloning to impersonate known individuals.

Watering hole attacks

Watering hole attacks are a targeted variant of website compromise where attackers deliberately infect sites frequented by a specific organization or industry group (trade publications, supplier portals, industry forums). When someone from the target visits the infected site, their browser executes malicious code — often a zero-day exploit — without warning signs. Distinguished by patience and precision: attackers research their targets, identify trusted destinations, and wait.