I don't think this attack can be used on a large scale because if the browser has a custom theme you will quickly notice that the popup is not from the browser. If it is used on one person, customizing the popup for his specific browser is almost impossible to notice it