For years, standard cybersecurity advice for browser users has been “don’t click on fishy links” and “don’t download anything.”
But today, browser-based attacks allow bad actors to gain access to a network without a user taking any action at all.
Sometimes just visiting a malicious website is enough to inadvertently grant access to a company’s system, Lionel Litty, chief information security officer at browser security company Menlo Security, told FinAi News.
“They may, at this point, be able to run code in the browser and, from there, potentially on your endpoint device,” Litty said.
FIs can be particularly vulnerable to this kind of attack because “they communicate with the outside world a lot,” Litty said. “They have analysts that need to do research and browse the internet. Sometimes they end up on websites that may be risky.”
Browser attacks are more widespread and harder to detect thanks to AI tools, with bad actors using AI to create credential-stealing pages and lure users to them, Karthik Vaidyalingam, field chief technology officer at data and AI security platform Varonis, said in a Sept. 1 webinar.
Convincing imitations
Mimicry has long been a strong tool in a cybercriminal’s arsenal. They can create malicious websites that resemble legitimate ones with similar URLs and they can build malware that looks like legitimate browser extensions.
IBM cybersecurity software IBM Trusteer identified one such fake Chrome extension, UnregStealer, in May.
UnregStealer looks like a legitimate Chrome extension. Once installed, it allows a cybercriminal to watch a victim’s browser activity in real-time, stealing information as the victim types it. UnregStealer targeted Latin American banks, according to IBM.
“The extension stays silent, leaves no trace and triggers no alert,” Itzhak Chimino, senior threat researcher at IBM, said in a June 16 blog post. “When the operator sees a session worth targeting — maybe a login page, payment confirmation or [money] transfer in progress — the attacker flips a switch.”
Even some of the most trusted websites can be convincingly spoofed. The FBI issued a warning on July 20 that cybercriminals have been spoofing its Internet Crime Complaint Center (IC3) website.
These sites “trick users into reporting crimes directly to attackers, but with additional details about their accounts and identities,” Varonis’ Vaidyalingam said in the webinar. “Because IC3 is normally considered a trusted reporting hub, it makes an ideal target.”
Fake security
Bad actors will even mimic browser security protocols to trick users into manually copying and pasting harmful system commands into their computers. These are called ClickFix attacks.
For example, a malicious site will mimic a CAPTCHA verification prompt to trick users into taking detrimental actions, Litty said.

“Attackers are playing on users’ frustrations,” he said. “The user thinks, ‘Oh, I have to solve this damn CAPTCHA to get to this content. It’s telling me I need to just hit Ctrl+V to paste this string and then I can get through the CAPTCHA.’
“But what happened behind the scenes is that now the attacker was able to run content on your endpoint that they should not have been able to run and you may end up having installed malicious software and be at the mercy of an attacker now.”
People spend upward of 80% to 90% of their computer time in a browser, making browser attacks highly attractive to cybercriminals, Litty said.
FinAi Lending Summit, set for Oct. 7-8 in Las Vegas, will include speakers from Fifth Third and Capital One as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee. To learn more about the 2026 event and register for early-bird pricing through Sept. 4, visit here.





