Why these two exist

Nearly every pixel on a web page belongs to the page. Logos, forms, padlock icons drawn in the content, "secure connection" banners: a phishing page can render whatever it wants there. The address bar is the exception: it is the browser's, not the page's, which is why it is the thing people are told to check. BitB and BitM are the two ways an attacker can get around that check without breaking the browser. One fakes the frame. The other makes the frame honest and moves the lie somewhere else.

They are often conflated, and the names do not help. They are different attacks, with different tells, and Grizzly sees them through different sensors.

Browser-in-the-Browser: the frame is painted

The technique was popularised by the researcher mr.d0x in 2022 as a fake single-sign-on popup, and templates have circulated since. Nothing is exploited and nothing is proxied: the page draws something that looks like a browser window, puts the brand's real-looking URL in its title area, and places a login form inside. The real address bar, above all of it, shows the attacker's host.

Grizzly's confirmed specimen is a Roblox kit at https://www---roblox.com/, a triple-hyphen look-alike domain, first seen on September 3rd, 2026. It is a two-stage page. The visitor first meets a fake "Verify you're human" gate. Past it sits a painted Chrome window, title "Roblox", address bar reading https://roblox.com/home with a padlock, and the Roblox login form inside.

- Impersonating

- Roblox

- URL

- https://www---roblox.com/

- Scanned

- September 3, 2026 · 21:25 UTC

Reasons

- Domain is not operated by Roblox

- DNS nameservers do not match Roblox's known infrastructure

- TLS certificate has no organization information

- Domain not registered through Roblox's usual registrar

The receipt above is the verdict Grizzly gives the page today. It did not get there on the first try, and the miss is instructive.

Grizzly reads a page two ways: as the text in the document, and as the pixels of a render. On this page the text told only half the story. The fake verification gate was ordinary markup; the painted window behind it, login form included, contributed no text at all. So the text read said "captcha page", captcha pages are not phishing, and ten consecutive scans came back neutral.

The fix was not to teach Grizzly what a fake browser window looks like. It was to stop trusting the text layer on a page that draws itself, and let the render decide. Seen as pixels, the page is a Roblox login on a domain Roblox does not operate, and the score follows. The same afternoon, the eleventh scan of www---roblox.com came back phish.

Browser-in-the-Middle: the frame is honest

BitM was described formally in 2021, and it has since been seen in real campaigns targeting MFA-protected accounts. The idea inverts BitB. The victim's address bar is telling the truth: it shows the attacker's host. But the page under it is not a web page in the usual sense. It is a live video of a browser running on the attacker's server, carried over the same remote-desktop technology that powers in-browser VNC clients, a technology with plenty of honest uses, which is part of what makes the attack hard to spot. That remote browser is open on the genuine site, and the victim's clicks and keystrokes are relayed into it.

There is no fake form to inspect, and the page passes every check that looks at content, because the content is genuine. What gives it away is the frame: a host that is not the brand's, serving a document that is nearly empty.

That is also what a scanner sees. The document itself is nearly empty, so Grizzly reads the render rather than the text, and the render is whatever the remote browser is showing.

- Impersonating

- URL

- https://whatsapp.avenormc.fun/

- Scanned

- September 20, 2026 · 19:24 UTC

Reasons

- Domain is not operated by WhatsApp

- DNS nameservers do not match WhatsApp's known infrastructure

- TLS certificate has no organization information

Look at the top-right of that render. "Restore pages? Chromium didn't shut down correctly" is a browser's own notification, and here it is rendered inside the page. Two sets of browser chrome on one screen means one of them is content. The vision pass read a WhatsApp login, Grizzly checked who operates the host, and the infrastructure did the rest.

What the two look like in production

Over the last six months BitM is the shape we see operated at scale. The hosts come in small farms: one rented server with gmail-browser, linkedin-browser, google-browser, tiktok-browser and instagram-browser as subdomains, and the same brand-per-subdomain pattern on a handful of other domains, more than a dozen hosts in all. Most of the time we arrived the stream was not running and the page was neutral, correctly, because nothing on it impersonated anyone. Twice it was live, both times on WhatsApp, and both were flagged. BitB is rarer in our data: one kit, scanned repeatedly over a week, always the same two-stage Roblox page.

A caution on those hostnames. A browser streamed from a server is not malicious in itself. It is how remote browser isolation products work, how people get around a network content filter or a country restriction, and how testers try a site from somewhere else. Plenty of the hosts we scanned were exactly that: someone's own browser container, with their own mail or chat open inside. They look identical to a lure at the hostname level, so the hostname is a reason to look, not a verdict. What decides is whether the remote browser is parked on a login page for whoever shows up.

Two honest limits: the BitB count is one kit, and the BitM farm count is by hostname shape, with the lure confirmed only where the stream was live when we scanned.

How to spot them yourself

- BitB: drag the login popup. A real one is its own window and can leave the browser; a painted one cannot. Then read the address bar at the very top, not the one near the form.

- BitM: the page behaves like a video. Text cannot be selected, zoom scales the picture, the cursor lags. Two sets of tabs or two address bars means one of them is content.

- Both: your own address bar is still the honest one. BitB hides it behind a fake; BitM leaves it visible and bets you will not read it.

Discussion

The two attacks are mirror images, and together they say where detection has to happen. A blocklist does not help until someone reports the host. A check that reads the page's own text is blind to both: in BitB the text describes a captcha, in BitM there is no text. What works is reading the render, the pixels the visitor actually faces, and asking two questions: who does this page claim to be, and does the host belong to them. Vision answers the first, infrastructure the second, and that pairing is what flagged both specimens.