
17.08.2026 browser-in-the-middlephishingsession-hijackingpasskeys
For years, FIDO2/WebAuthn was considered the gold standard against phishing because its cryptographic signature is bound to the origin domain. Browser-in-the-Middle (BitM) defeats that promise entirely — not through an exploit, but through a deceptively simple trick: the victim never types into a fake page. They type into their own genuine browser, which just happens to be streamed from a server the attacker controls.
Technically, the method usually relies on noVNC, a browser-based VNC client. VNC lets one computer remotely control another’s desktop, and noVNC allows this remote control to happen inside a browser using only HTML5 and JavaScript. The attacker runs a real Chrome or Firefox process on their own infrastructure, opens the legitimate login page inside it, and streams that browser session to the victim. From the victim’s perspective it looks like an ordinary tab — the attacker sets up a “transparent” remote browser on their own infrastructure. Because authentication genuinely occurs within the real domain’s context, WebAuthn origin checks pass without issue: it’s as if the victim is using a browser, but it’s actually running on the attacker’s machine, with every action including the authentication step mirrored and recorded by the attacker’s tooling.
A campaign documented by Palo Alto Networks’ Unit 42 illustrates the pattern in the wild: active since at least April 2025, it uses BitM to harvest Meta/Facebook credentials, starting with weaponized links in phishing emails that redirect victims to a fake CAPTCHA page, which then triggers a deceptive in-page fake browser window impersonating Facebook’s login popup while displaying what looks like a legitimate URL.
The critical forensic insight here is that hardware tokens and passkeys don’t provide full protection once the session layer itself remains attackable. The user authenticates successfully with their passkey, but the attacker holds the result of that authentication — passwordless environments carry the same session-layer exposure as password-based ones. Once login succeeds, the application issues a session cookie that the attacker simply reads from their own remote session in plaintext — not theft in the classic sense, but real-time capture.
For forensic practice this has an uncomfortable implication: classic endpoint artifacts on the victim’s machine are often empty, because the actually-compromised process never ran there. Investigators must shift toward server-side and network-based signals instead.
Concrete starting points for incident response:
The deeper structural challenge remains, though: as long as sessions are trusted once authentication succeeds, even the strongest initial authentication is meaningless without continuous validation of the session layer itself. BitM is a clear signal that DFIR teams need to shift their focus from “how did the attacker get in?” to “which session is alive right now, and where?”
← Back to overview