Phishing

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.

Future phishing campaigns may no longer involve a detectable physical web page.

Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.

The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication.

A crafted redirect routes the user to Microsoft Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser into the blob URL that renders the phishing page existing only within the browser.

Since this process is wrapped up in trusted Microsoft assets, it has all the hallmarks of being trustworthy and is likely to trigger no alarms, providing improved stealth over traditional static external phishing web pages.

The blob-created phishing page exists solely within the victim’s browser. Barracuda’s analysis shows that service workers, iframes and backend controls manage the subsequent phishing workflow and user navigation. A hidden command and control configuration also demonstrates that this automatically constructed phishing page is not a simple stand-alone, but part of a managed platform that can be centrally operated, updated and steered across multiple victims simultaneously.

Advertisement. Scroll to continue reading.

This campaign demonstrates that attackers’ use of blob URL-created phishing pages can add greater flexibility as well as improved stealth to phishing. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains and reducing many of the indicators that security teams have traditionally relied upon for detection,” write the researchers. There is no phishing page to block.

Future phishing detection, say the researchers, will require greater emphasis on identity protection, browser security and behavioral detection – there is no physical page that might trigger an alarm. Techniques should include closer inspection of browser activity involving blob URLs; monitoring OAuth authorization flows for unexpected destinations; and using email security controls that analyze the full click path rather than relying solely on the initial URL.

Related: New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Related: FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

Related: Over 500 Organizations Hit in Years-Long Phishing Campaign

Related: Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations

Related Content

Cybercrime

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard.

Mobile & Wireless

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.

Phishing

The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.

Phishing

The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.

Phishing

Victims span across the aviation, critical infrastructure, energy, logistics, public administration, and technology sectors.

Phishing

The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM.

Phishing

Still under development, Bluekit provides users with automated domain registration and an AI Assistant.

Phishing

Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version