# Google Phishing Kit Uses Real-Time Browser-in-the-Middle (Socket.IO) Remote Browser Relay

> Joe Security analyzed a Google sign-in phishing kit that implements a Browser-in-the-Middle (BitM) architecture: the victim's page relays every keystroke, click and selection to a backend browser over Socket.IO and applies the backend's DOM changes (via diffDOM) in return. The kit is gated by Cloudflare Turnstile and delivers an encrypted self-decrypting loader; no attribution or CVE is reported.

- **Published:** 2026-08-11T00:00:00Z
- **Last reviewed:** 2026-08-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3036
- **ID:** TL-2026-3036
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 9 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Joe Security (blog post dated 11.08.2026, parsed as 2026-08-11) documents a phishing kit that mimics the Google authentication flow but is not a static clone. It is a Browser-in-the-Middle / adversary-in-the-middle design in which the victim-facing page is only a thin client for a browser session running on the attacker's backend. The backend streams complete Google authentication views and subsequent DOM updates to the victim over Socket.IO, while the victim's browser sends full field state and user interactions in the opposite direction. The backend can therefore drive a multi-step authentication flow while the victim stays on the malicious origin.

Delivery and gating: the first request to the phishing origin returns a Cloudflare Turnstile challenge. After the challenge is completed the server sets three cookies with a 3-minute lifetime, one of which is viewer_session_id, and redirects to an encrypted application loader that carries its own self-decryption material. The decrypted loader pulls three JavaScript components from the phishing origin: socket.io-client.js (Socket.IO transport), domdiffer.js (a reformatted browser build of the open-source fiduswriter/diffDOM library) and index.js (custom relay and control logic).

Relay protocol: the client emits inputchange (full input value, CSS path, selectionStart/selectionEnd and element metadata), selectionchange (caret movement) and click events, capturing normal input, paste, IME composition and change events, and calling preventDefault/stopPropagation on user interactions. The server emits domchanges (diff arrays applied to head, body and nested iframes through diffDOM), inputchange (server-directed field updates with selection restoration), navigation commands with URL rewriting that keeps the victim on the malicious origin, and flow-control signals (document reset, pause, completion redirect). A client-side inputTracker suppresses outbound events that match server-supplied values to avoid feedback loops. Because authentication evolves through continuous state exchange rather than a form POST and reload, there is no conventional credential submission for network tooling to key on; pre-rendered elements such as a hiddenPassword field reference were seen in the patches delivered after the email step.

Evidence: Joe Sandbox reproduced a live session (analysis 1951180) showing a pixel-faithful Google sign-in UI. TLS inspection exposed plaintext Engine.IO/Socket.IO framing: 90 protocol records with 74 application events, most after the HTTP-to-WebSocket upgrade. A Joe Reverser expert-mode analysis recovered the decryption mechanism and JavaScript components. Only one network indicator is published, the domain salemilaw[.]com. The analyst did not state the delivery vector (lure), the victim set, the actor, or whether the domain is attacker-registered or a compromised legitimate site; none is asserted here. A BeaconBeagle config search for the domain returned no records, and open web search found no other reporting on it.

Analyst note: the report states the kit relays the full authentication flow, which is the property that makes BitM effective against password-plus-MFA sign-ins (the same mechanism described for the public CuddlePhish BitM tool), but the Joe write-up does not itself show MFA or session-cookie theft, so those capabilities are treated as a risk, not an observed behavior. A separate, apparently unrelated Google credential kit reported by cside (July 2026) uses image-streamed remote-browser rendering over encrypted WebSockets rather than Socket.IO/diffDOM and is cited for context only; its indicators are not merged into this record.

## MITRE ATT&CK

- T1557 Adversary-in-the-Middle
- T1056 Input Capture
- T1684.001 Impersonation
- T1480 Execution Guardrails
- T1027 Obfuscated Files or Information
- T1071.001 Web Protocols

## Sources

- [Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser (Joe Security)](https://www.joesecurity.org/blog/2909557602925734728)
- [Joe Sandbox Analysis 1951180 (live phishing session)](https://www.joesandbox.com/analysis/1951180/0/html)
- [Joe Sandbox TLS-inspected capture for analysis 1951180](https://www.joesandbox.com/analysis/1951180/0/pcapsslinspection)
- [Joe Reverser expert-mode report (loader decryption and JS components)](https://www.joesandbox.com/joereverser/analysis/50aaf3fa-65c5-47a7-8b8b-c8508909340e/download?type=reports&report=html)
- [Socket.IO conversation extraction script (Appendix A of the Joe post)](https://pastebin.com/MRYaTCvp)
- [fiduswriter/diffDOM (library reused in domdiffer.js)](https://github.com/fiduswriter/diffDOM)
- [SpecterOps CuddlePhish docs: Browser-in-the-Middle overview](https://docs.specterops.io/cuddlephish-docs/overview.md)
- [cside: Inside a live Google credential phishing kit (related, distinct kit)](https://cside.com/blog/inside-live-google-credential-phishing-kit)
- [MITRE ATT&CK T1557 Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3036
