UPDATED 09:00 EST / JANUARY 12 2026

SECURITY

Trellix warns of advanced Facebook phishing using browser-in-the-browser attacks

A new report out today from cybersecurity company Trellix Inc. warns that Facebook phishing scams are becoming significantly more sophisticated, as attackers increasingly abuse legitimate cloud infrastructure and employ advanced visual deception techniques to steal user credentials.

According to the report, attackers have moved beyond traditional phishing emails and fake login pages and are adopting a technique known as “browser-in-the-browser.”

The method involves creating a fully simulated login pop-up window inside a user’s browser tab that closely mimics a legitimate Facebook authentication prompt. Because the fake window displays what appears to be a real Facebook URL, users have little visual indication that their credentials are being harvested rather than sent to Meta Platforms Inc.’s servers.

The phishing campaigns often start with phishing emails designed to look like official communications from law firms or Meta and often allege copyright violations, account suspensions, or suspicious login activity. The potential victims are then directed to click on a link and are then presented with the deceptive BitB login window.

Not surprisingly, at this point, once credentials are entered, the attackers can completely take over Facebook accounts to spread further scams, steal personal data or conduct identity fraud.

The campaign also becomes more interesting in that instead of relying on malicious domains, attackers have been found to be increasingly deploying fake Facebook login and appeal pages on services such as Netlify Inc. and Vercel Inc. The idea here is that by hosting phishing content on reputable cloud providers and masking links with URL shorteners, the attackers can evade many traditional email and web security filters while giving victims a false sense of legitimacy.

In examples given in the report, users were first prompted to submit basic personal information, including names, email addresses, phone numbers and dates of birth, before being asked to enter their Facebook passwords to complete an appeal or security check. Trellix’s researchers note that this multi-step approach increases the perceived authenticity of the process and improves credential theft success rates.

The researchers warn that the rise of BitB attacks represents an escalation in phishing tactics because visual inspection alone is no longer a reliable defense, arguing that even experienced users may struggle to distinguish a fake in-browser login window from a genuine authentication flow.

Trellix is recommending that all Facebook users enable two-factor authentication on their accounts, avoid clicking links in unsolicited emails and manually navigate to facebook.com or the official mobile app to verify account issues.

Image: SiliconANGLE/Ideogram

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.