Instead of sending victims to a hosted credential-harvesting page, the attackers generate the phishing page directly inside ...