---
title: "Don't Take The Bait: How To Identify Advanced Phishing Techniques"
description: Advanced phishing schemes and how one can avoid and identify them.
image: https://blog.seedspark.com/hubfs/ezgif-1-cd9b0119da.jpeg
---

[![logo-white-2020](https://blog.seedspark.com/hs-fs/hubfs/logo-white-2020.png?width=80&height=80&name=logo-white-2020.png "logo-white-2020")](https://seedspark.com/)

[![logo-square](https://blog.seedspark.com/hs-fs/hubfs/logo-square.png?width=55&height=54&name=logo-square.png "logo-square")](https://seedspark.com/)

[![Contact Us](https://no-cache.hubspot.com/cta/default/1546797/3ad3da3a-9602-4c46-afb0-274659a1f959.png)](https://cta-redirect.hubspot.com/cta/redirect/1546797/3ad3da3a-9602-4c46-afb0-274659a1f959)

- [**](https://www.facebook.com/sharer/sharer.php?u=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&title=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques&description=Advanced%20phishing%20schemes%20and%20how%20one%20can%20avoid%20and%20identify%20them.)
- [**](https://twitter.com/intent/tweet?source=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&text=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques%20-%20https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics)
- [**](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&title=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques&summary=Advanced%20phishing%20schemes%20and%20how%20one%20can%20avoid%20and%20identify%20them.)

14 April 2022 Thursday

# Don't Take The Bait: How To Identify Advanced Phishing Techniques

By [Kevin Kuhlman](https://blog.seedspark.com/blog/author/kevin-kuhlman)

To avoid being victimized by phishing sites, we usually advise examining the address bar for HTTPS presence, avoiding domains with questionable characters like g00gle.com, and discouraging clicking on any recurring or suspicious pop-ups. But what if someone discovered a method to phish passwords without including these characteristics?

One researcher devised a method to completely spoof an OAuth page. It's called a **BitB**, short for "browser in the browser," which uses a fake browser window within a genuine browser window to mimic an OAuth page. Thousands of websites utilize the OAuth protocol to enable users to log in using their existing accounts with companies like Google, Apple, and Facebook. Instead of having to create an account on the new site, visitors can use an account that they already have—and the magic of OAuth does the rest.

---

## Exploiting User Trust

The photo editing site Canva, for instance, gives visitors the option to login using popular account platforms like Google and Facebook. When accessing the account, after clicking the "sign in" button, a new browser window appears over the top of the existing Canva window.

![FOIhfslXIBkKzS-](https://blog.seedspark.com/hs-fs/hubfs/FOIhfslXIBkKzS-.jpeg?width=700&name=FOIhfslXIBkKzS-.jpeg)

The OAuth procedure guarantees that only Google has access to the user's password. Canva never sees the login information. Instead, OAuth establishes a login session with Google and, when the username and password check out, Google provides the user with a token that allows access to Canva. (Services like PayPal work in a similar manner.)

The BitB approach takes advantage of this method. Instead of creating a genuine second browser window that is linked to the site enabling logins or payments, BitB employs a number of HTML and cascading style sheet (CSS) methods to convincingly impersonate the second window. The fake website has a valid address, complete with a padlock and HTTPS prefix. The window's appearance and operation are identical to the genuine thing. However, it is deployed and strategically designed to exploit the user's privacy.

Last week, a researcher using the handle "mr.d0x" revealed the method. His proof-of-concept attack begins with a web page that accurately imitates Canva. When a visitor logs in using their Apple, Google, or Facebook credentials, a phony Canva page opens a new web page that appears to be the same as the genuine OAuth site.

This new page is also a spoof, with all of the visuals that come the standard Google login. The page also includes the proper Google website address in the address bar. The new window works similarly to a browser window when connected to a genuine Google OAuth session.

If a potential victim opens the fake Canva.com page and tries to login with Google, “it will open a new browser window and go to [what appears to be] the URL accounts.google.com,” mr.d0x wrote. In actuality, the fake Canva site “doesn’t open a new browser window. It makes it LOOK like a new browser window was opened but it’s only HTML/CSS. Now that fake window sets the URL to accounts.google.com, but that's an illusion.”

## Know The Signs

The BitB approach is straightforward and effective enough that it's surprising no one has heard of it before. After mr.d0x published about the technique, a few fellow researchers stated how easy it would be for even more seasoned Web users to fall for the ruse.

![canva.jpg](https://blog.seedspark.com/hs-fs/hubfs/canva.jpg.webp?width=730&name=canva.jpg.webp)

“This browser-in-the-browser attack is perfect for phishing,” one developer wrote. “If you're involved in malvertising, please don't read this. We don't want to give you ideas.”

This method has previously been employed. In 2020, Zscaler observed a BitB attack used in order to gain access credentials for the popular video game distribution platform, Steam.

The technique, on the other hand, has a few flaws that should offer savvy visitors a foolproof method to determine if something is wrong. Genuine OAuth or payment windows are individual browser instances that are distinct from the primary window. That implies they may be dragged anywhere, including onto the main window's address bar.

The phony websites don't cover the main browser window's address bar, because they're not a separate browser instance. Instead, they're created by custom HTML and CSS and housed within the primary window, which means they can't be covered by fake pages from an alternative program.

Two-factor authentication should be used by everyone who uses Google, Apple, or Facebook. More experienced users can also use the right-click menu on the popup page to "inspect." The URL of a BitB spawn will be hardcoded into the HTML if it is a window created by BitB.

It wouldn't be unusual to discover that the BitB approach has been more widely used, yet mr.d0x's responses demonstrate that even many security defenders are unaware of it, implying that a large number of end users aren't aware of it, either.

[You can read more from ARS Technica here.](https://arstechnica.com/information-technology/2022/03/behold-a-password-phishing-site-that-can-trick-even-savvy-users/?utm_social-type=owned&utm_brand=ars&utm_source=twitter&utm_medium=social)

 

SeedSpark is a trusted technology resource for small- and medium-sized businesses. From laptop provisioning to new accessories, we’re helping teams connect and communicate with other teams across the country each day. **Complete the form and contact our team for a free 30-minute technology assessment.** We’ll take time to learn more about your existing technology, assess the situation, and identify new opportunities for improvement that can help you make the most of your technology.

Share:

- [**](https://www.facebook.com/sharer/sharer.php?u=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&title=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques&description=Advanced%20phishing%20schemes%20and%20how%20one%20can%20avoid%20and%20identify%20them.)
- [**](https://twitter.com/intent/tweet?source=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&text=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques%20-%20https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics)
- [**](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics&title=Don't%20Take%20The%20Bait:%20How%20To%20Identify%20Advanced%20Phishing%20Techniques&summary=Advanced%20phishing%20schemes%20and%20how%20one%20can%20avoid%20and%20identify%20them.)

### Written by [Kevin Kuhlman](https://blog.seedspark.com/blog/author/kevin-kuhlman)

As SeedSpark's Social Media & Content Specialist, Kevin takes pride in managing the online social presence of SeedSpark and their clients.

 PREVIOUS POST  
[** Which 2FA Should You Use? ](https://blog.seedspark.com/blog/which-2fa-should-you-use)

[**](https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics#top)

 Next Post  
[5 Easy Ways to Spring Clean Your Devices **](https://blog.seedspark.com/blog/5-easy-ways-to-spring-clean-your-devices)

[Content Title](https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics#)

Description

### Search

### Recent Posts

[ Building a Resilient Business: Strategies for Navigating Economic Uncertainty ](https://blog.seedspark.com/blog/building-a-resilient-business-strategies-for-navigating-economic-uncertainty)

[Chad Jenkins](https://blog.seedspark.com/blog/author/chad-jenkins) Feb 1, 2024

[ Harnessing Data for Business Success: A Comprehensive Guide to Data-Driven Decision-Making ](https://blog.seedspark.com/blog/harnessing-data-for-business-success-a-comprehensive-guide-to-data-driven-decision-making)

[Chad Jenkins](https://blog.seedspark.com/blog/author/chad-jenkins) Jan 8, 2024

[ Top Business Trends of 2024: Strategies for Growth and Success ](https://blog.seedspark.com/blog/top-business-trends-of-2024-strategies-for-growth-and-success)

[Chad Jenkins](https://blog.seedspark.com/blog/author/chad-jenkins) Jan 4, 2024

[ Empowering Organizations with CISA's Cybersecurity Awareness Month 2023 Toolkit ](https://blog.seedspark.com/blog/empowering-organizations-with-cisas-cybersecurity-awareness-month-2023-toolkit)

[Patrick Kinsley](https://blog.seedspark.com/blog/author/patrick-kinsley) Oct 26, 2023

[ Four Essential Steps to Enhance Your Online Safety ](https://blog.seedspark.com/blog/four-essential-steps-to-enhance-your-online-safety)

[Patrick Kinsley](https://blog.seedspark.com/blog/author/patrick-kinsley) Oct 19, 2023

### Popular Posts

[ The 8 Best Productivity Tools Included with Microsoft 365 ](https://blog.seedspark.com/blog/meet_office365)

[Samuel Adams](https://blog.seedspark.com/blog/author/samuel-adams) - Apr 21, 2021

[ Bots Are Stealing MFA Codes and Accessing Accounts - The New Cyber Threat in 2021 ](https://blog.seedspark.com/blog/mfa-code-stealing)

[Samuel Adams](https://blog.seedspark.com/blog/author/samuel-adams) - Nov 3, 2021

[ What is Windows 11 S Mode and Should You Use It? ](https://blog.seedspark.com/blog/windows11-smode)

[Samuel Adams](https://blog.seedspark.com/blog/author/samuel-adams) - Sep 17, 2021

[ Alternatives to Using SMS for 2-factor Authentication ](https://blog.seedspark.com/blog/alternatives-to-using-sms-for-2-factor-authentication)

[Robert Griffin](https://blog.seedspark.com/blog/author/robert-griffin) - Mar 9, 2023

[ How to Use Shifts in Microsoft Teams for Your Organization ](https://blog.seedspark.com/blog/shifts_microsoft_teams)

[Samuel Adams](https://blog.seedspark.com/blog/author/samuel-adams) - Jul 2, 2020

## Growth Is Just One Click Away

Want to chat? Just share some project details and a member of our sales team will be in touch to learn more about your vision and how we can help!

 

##### How can we grow together?

[![Call Now](https://no-cache.hubspot.com/cta/default/1546797/e8917216-677b-4754-8a92-11da535e5577.png)](https://cta-redirect.hubspot.com/cta/redirect/1546797/e8917216-677b-4754-8a92-11da535e5577)

## Join Our Newsletter

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Kevin Kuhlman",
    "url" : "https://blog.seedspark.com/blog/author/kevin-kuhlman"
  },
  "dateModified" : "2022-04-14T14:50:14.432Z",
  "datePublished" : "2022-04-14T14:50:14.000Z",
  "headline" : "Don't Take The Bait: How To Identify Advanced Phishing Techniques",
  "image" : [ "https://blog.seedspark.com/hubfs/ezgif-1-cd9b0119da.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.seedspark.com/blog/dont-take-the-bait-how-to-identify-advanced-phishing-tactics",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.seedspark.com/hubfs/SS_Logo_R_Blue_Horizontal.svg"
    },
    "name" : "SeedSpark"
  }
}
```