“With 89% of phishing domains active for fewer than two days, organizations relying on blocklists are playing a losing game.”
Phishing for credentials and sessions: kits and delivery have evolved
Phishing is no longer a one-off email trick. Reverse-proxy adversary-in-the-middle (AiTM) kits such as Tycoon2FA, Sneaky2FA, and Evilginx relay credentials and session tokens in real time, bypassing most forms of multi‑factor authentication. These kits are sold as turnkey Phishing‑as‑a‑Service platforms that include anti‑bot protection, dynamic lure generation, and automated session replay, effectively lowering the barrier to sophisticated phishing to nearly zero.
Delivery channels have also proliferated beyond email: Push data shows roughly one in two phishing attacks is delivered outside of email via instant messaging, social media, SMS, malicious ads, and in‑app messaging. Short-lived infrastructure compounds the problem—most phishing domains disappear within 48 hours—so blocklists and signature‑based controls struggle to keep pace.
ClickFix and malicious copy‑and‑paste: the browser as a lure and the endpoint as the detonation point
Since late 2024 attackers have been abusing the human instinct to copy and paste “fixes.” Microsoft's Digital Defense Report identified ClickFix as the most common initial access vector, accounting for 47% of observed attacks, and Push detections put ClickFix at 52% of total detections in Q2 2026. The pattern is consistent: a browser lure—often a fake CAPTCHA or verification challenge—tricks a user into copying and executing commands locally. That local execution typically installs Remote Access Tools or infostealer malware.
Four in five ClickFix payloads observed by Push are accessed from search engines via compromised sites, malvertising, and SEO poisoning, routinely bypassing email security. Variants continue to appear: InstallFix replaces legitimate install commands on malvertised pages for developer tools, and the LLMShare campaign delivered malware via shared conversations on AI chatbot platforms hosted on trusted domains. All share a single common step: a malicious copy‑and‑paste event inside the browser.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAuthorization phishing: abusing consent, device codes, and token exchanges
A class of attacks now targets the post‑login phase. Authorization phishing manipulates OAuth flows—consent grants, device code flows, and token exchanges—to obtain access tokens without touching the authentication step, rendering MFA and even phishing‑resistant passkeys irrelevant. Three techniques fall into this category: consent phishing (victims authorize malicious third‑party apps), device code phishing (abusing RFC 8628 device authorization grants), and hybrids such as ConsentFix, a ClickFix‑OAuth mixture first observed in Russian APT29 campaigns and since commoditized.
Push tracks more than 30 distinct kits offering device code phishing, underscoring that these are not isolated nation‑state tricks but widely available tools in the criminal ecosystem.
Malicious browser extensions and AI add‑ons: supply‑chain and configuration risks
Malicious extensions steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. Attackers commonly acquire legitimate extensions and push a malicious update once install counts reach impact thresholds. Push found that 46.76% of extensions have permission combinations sufficient for account takeover with no user interaction.
AI browser extensions expand the attack surface. The Verizon DBIR 2026 reported that more than 15% of corporate users had unauthorized AI browser extensions installed; Push found an average of 17 unique AI extensions per company and one team running 163. These AI extensions create data exfiltration pathways that sit outside traditional DLP controls. Static risk scoring proved a poor predictor of compromise across recent extension supply‑chain incidents; the recommended control is a default‑deny approach with allowlisting plus monitoring for change events rather than blind reliance on risk scores.
Credential stuffing, ghost logins, and session hijacking: the persistence problem
Password‑based compromise remains a leading cause of breaches because single sign‑on is not universal. Of the last million logins observed by Push, one in four were password logins (not SSO), two in five were not protected by MFA, and one in five used a weak, breached, or reused password. Cloudflare's 2026 Threat Report found 63% of all human logins involve credentials already compromised elsewhere.
That gap produces ghost logins—backup credentials created at app adoption and invisible to identity provider logs unless explicitly disabled. Session hijacking is the logical follow‑through: stolen session tokens, often harvested by infostealer malware delivered via ClickFix, are replayed in an attacker’s browser to bypass authentication entirely. Verizon DBIR 2025 found that 46% of infostealer infections that led to corporate breaches originated on non‑managed devices—personal machines, developer workstations, and contractor laptops where EDR is absent—while browser sync features can bridge personal account compromises directly into corporate environments.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: expect most of the attack chain to originate and complete inside the browser. Controls that detect and block browser‑based techniques in real time, including AiTM phishing and ClickFix, are the defensive priority Push recommends; allowlisting extensions and monitoring for updates addresses supply‑chain risk better than static scoring.
- Procurement and identity owners: SSO gaps and shadow IT matter. The prevalence of password logins and ghost credentials means SSO adoption and explicit disabling of legacy login methods need to be tracked; device‑code and consent phishing show identity design can be abused even when authentication is intact.
- End users and teams that run developer tools: copying and pasting commands is an exploitable behavior. Many campaigns—from InstallFix to LLMShare—depend on a malicious copy‑and‑paste event in the browser; awareness and operational controls that prevent running unvetted commands are critical.
The modern breach increasingly begins and often ends in the browser. Short‑lived phishing domains, commoditized AiTM and device‑code kits, copy‑and‑paste lures, and malicious extension updates have combined to make browser‑based attacks the default attack surface in 2026. Defenders who continue to treat email, network, or endpoint controls as sufficient will find themselves chasing an adversary that lives where users work: in the browser. A practical next step reflected in the data is clear—shift detection and prevention closer to the browser session, adopt default‑deny extension policies, and close SSO gaps so that stolen tokens and ghost logins have fewer places to hide.
https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html




