Skip to content
frameless

frameless

Sploitus • September 17, 2026

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login pages like Microsoft.

This POC code is built for using this new BITB with Evilginx, and a Microsoft Enterprise phishlet.

![Frameless-BITB-DEMO-compressed](

Before diving deep into this, I recommend that you first check my talk at BSides 2023, where I first introduced this concept along with important details on how to craft the "perfect" phishing attack. ▶ Watch Video

This tool is for educational and research purposes only. It demonstrates a non-iframe based Browser In The Browser (BITB) method. The author is not responsible for any misuse. Use this tool only legally and ethically, in controlled environments for cybersecurity defense testing. By using this tool, you agree to do so responsibly and at your own risk.

Over the past year, I've been experimenting with different tricks to craft the "perfect" phishing attack. The typical "red flags" people are trained to look for are things like urgency, threats, authority, poor grammar, etc. The best thing people nowadays check is the link/URL of the website they are interacting with, and they tend to get very conscious the moment they are asked to enter sensitive credentials like emails and passwords.

That's where Browser In The Browser (BITB) came into play. Originally introduced by @mrd0x, BITB is a concept of creating the appearance of a believable browser window inside of which the attacker controls the content (by serving the malicious website inside an iframe). However, the fake URL bar of the fake browser window is set to the legitimate site the user would expect. This combined with a tool like Evilginx becomes the perfect recipe for a believable phishing attack.

The problem is that over the past months/years, major websites like Microsoft implemented various little tricks called "framebusters/framekillers" which mainly attempt to break iframes that might be used to serve the proxied website like in the case of Evilginx.

In short, Evilginx + BITB for websites like Microsoft no longer works. At least not with a BITB that relies on iframes.

A Browser In The Browser (BITB) without any iframes! As simple as that.

Meaning that we can now use BITB with Evilginx on websites like Microsoft.

Evilginx here is just a strong example, but the same concept can be used for other use-cases as well.

Framebusters target iframes specifically, so the idea is to create the BITB effect without the use of iframes, and without disrupting the original structure/content of the proxied page. This can be achieved by injecting scripts and HTML besides the original content using and replace (aka substitutions), then relying completely on HTML/CSS/JS tricks to make the visual effect. We also use an additional trick called "Shadow DOM" in HTML to place the content of the landing page (background) in such a way that it does not interfere with the proxied content, allowing us to flexibly use any landing page with minor additional JS scripts.

![Thumbnail with YouTube Player](

Create a local Linux VM. (I personally use Ubuntu 22 on VMWare Player or Parallels Desktop)

Create a new evilginx user, and add user to sudo group:

Test that evilginx user is in sudo group:

(You can do everything as sudo user as well since we're running everything locally)

Download and build Evilginx: Official Docs

wget

sudo tar -C /usr/local -xzf go1.21.4.linux-amd64.tar.gz

ADD: `export PATH=$PATH:/usr/local/go/bin`

Create a new directory for our evilginx build along with phishlets and redirectors:

cp / /evilginx/evilginx2/build/evilginx / /evilginx/evilginx/evilginx

cp -r / /evilginx/evilginx2/redirectors / /evilginx/evilginx/redirectors

cp -r / /evilginx/evilginx2/phishlets / /evilginx/evilginx/phishlets

Ubuntu firewall quick fix (thanks to @kgretzky)

sudo setcap CAP_NET_BIND_SERVICE=+eip / /evilginx/evilginx/evilginx

On Ubuntu, if you get `Failed to start nameserver on: :53` error, try modifying this file

edit/add the `DNSStubListener` to `no` > `DNSStubListener=no`

Since we will be using Apache2 in front of Evilginx, we need to make Evilginx listen to a different port than 443.

Enable Apache2 mods that will be used: (We are also disabling access_compat module as it sometimes causes issues)

Try if Apache and VM networking works by visiting the VM's IP from a browser on the host machine.

git clone

Make directories for the pages we will be serving:

* : (Optional) Homepage (at base domain)

Optional: Remove the default Apache page (not used):

Copy the O365 phishlet to phishlets directory:

sudo cp ./O365.yaml / /evilginx/evilginx/phishlets/O365.yaml

**Optional:** To set the Calendly widget to use your account instead of the default I have inside, go to `pages/primary/script.js` and change the `CALENDLY_PAGE_NAME` and `CALENDLY_EVENT_TYPE`.

**Note on Demo Obfuscation:** As I explain in the walkthrough video, I included a minimal obfuscation for text content like URLs and titles of the BITB. You can open the demo obfuscator by opening `demo-obfuscator.html` in your browser. In a real-world scenario, I would highly recommend that you obfuscate larger chunks of the HTML code injected or use JS tricks to avoid being detected and flagged. The advanced version I am working on will use a combination of advanced tricks to make it nearly impossible for scanners to fingerprint/detect the BITB code, so stay tuned.

Since we are running everything locally, we need to generate self-signed SSL certificates that will be used by Apache. Evilginx will not need the certs as we will be running it in developer mode.

We will use the domain `fake.com` which will point to our local VM. If you want to use a different domain, make sure to change the domain in all files (Apache conf files, JS files, etc.)

Create dir and parents if they do not exist:

sudo mkdir -p /etc/ssl/localcerts/fake.com/

Generate the SSL certs using the OpenSSL config file:

sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 \

-keyout /etc/ssl/localcerts/fake.com/privkey.pem -out /etc/ssl/localcerts/fake.com/fullchain.pem \

sudo chmod 600 /etc/ssl/localcerts/fake.com/privkey.pem

Copy custom substitution files (the core of our approach):

sudo cp -r ./custom-subs /etc/apache2/custom-subs

**Important Note:** In this repo I have included 2 substitution configs for Chrome on Mac and Chrome on Windows BITB. Both have auto-detection and styling for light/dark mode and they should act as base templates to achieve the same for other browser/OS combos. Since I did not include automatic detection of the browser/OS combo used to visit our phishing page, you will have to use one of two or implement your own logic for automatic switching.

Both config files under `/apache-configs/` are the same, only with a different Include directive used for the substitution file that will be included. (there are 2 references for each file)

# Uncomment the one you want and remember to restart Apache after any changes:

#Include /etc/apache2/custom-subs/win-chrome.conf

Include /etc/apache2/custom-subs/mac-chrome.conf

Simply to make it easier, I included both versions as separate files for this step.

sudo cp ./apache-configs/win-chrome-bitb.conf /etc/apache2/sites-enabled/000-default.conf

sudo cp ./apache-configs/mac-chrome-bitb.conf /etc/apache2/sites-enabled/000-default.conf

Test Apache configs to ensure there are no errors:

Get the IP of the VM using `ifconfig` and note it somewhere for the step.

We now need to add new entries to our hosts file, to point the domain used in this demo `fake.com` and all used subdomains to our VM on which Apache and Evilginx are running.

Open Notepad as Administrator ( > Notepad > Right-Click > Run as Administrator)

Click on the File option (top-left) and in the File Explorer address bar, copy and paste the following:

Change the file types (bottom-right) to "All files".

Now modify the following records (replace `[IP]` with the IP of your VM) then paste the records at the end of the hosts file:

Now restart your browser before moving to the step.

**Note:** On Mac, use the following command to flush the DNS cache:

`sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder`

This demo is made with the provided Office 365 Enterprise phishlet. To get the host entries you need to add for a different phishlet, use `phishlet get-hosts [PHISHLET_NAME]` but remember to replace the `127.0.0.1` with the actual local IP of your VM.

Since we are using self-signed SSL certificates, our browser will warn us every time we try to visit `fake.com` so we need to make our host machine trust the certificate authority that signed the SSL certs.

For this step, it's easier to follow the video instructions, but here is the gist anyway.

Open in your Chrome browser.

Ignore the Unsafe Site warning and proceed to the page.

Click the SSL icon > Details > Export Certificate **IMPORTANT:** When saving, the name MUST end with .crt for Windows to open it correctly.

Double-click it > install for current user. Do NOT select automatic, instead place the certificate in specific store: select "Trusted Route Certification Authorities".

**On Mac:** to install for current user only > select "Keychain: login" **AND** click on "View Certificates" > details > trust > Always trust

You should be able to visit ` now and see the homepage without any SSL warnings.

At this point, everything should be ready so we can go ahead and start Evilginx, set up the phishlet, create our lure, and test it.

Optional: Install tmux (to keep evilginx running even if the terminal session is closed. Mainly useful when running on remote VM.)

Start Evilginx in developer mode (using tmux to avoid losing the session):

(To re-attach to the tmux session use `tmux attach-session -t evilginx`)

**IMPORTANT:** Set Evilginx Blacklist mode to NoAdd to avoid blacklisting Apache since all requests will be coming from Apache and not the actual visitor IP.

Copy the lure URL and visit it from your browser (use Guest user on Chrome to avoid having to delete all saved/cached data between tests).

Original iframe-based BITB by @mrd0x:

Evilginx Mastery Course by the creator of Evilginx @kgretzky:

My talk at BSides 2023:

How to protect Evilginx using Cloudflare and HTML Obfuscation:

Evilginx resources for Microsoft 365 by @BakkerJan:

* Create script(s) to automate most of the steps

Extracted Entities

Domains (1)