Back Securityweek New Phishing Attack Creates Malicious Pages Inside the Victim's Browser
Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.
The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication.
A crafted redirect routes the user to Microsoft Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser into the blob URL that renders the phishing page existing only within the browser.
Since this process is wrapped up in trusted Microsoft assets, it has all the hallmarks of being trustworthy and is likely to trigger no alarms, providing improved stealth over traditional static external phishing web pages.
The blob-created phishing page exists solely within the victim’s browser. Barracuda’s analysis shows that service workers, iframes and backend controls manage the subsequent phishing workflow and user . A hidden command and control configuration also demonstrates that this automatically constructed phishing page is not a simple stand-alone, but part of a managed platform that can be centrally operated, updated and steered across multiple victims simultaneously.
This campaign demonstrates that attackers’ use of blob URL-created phishing pages can add greater flexibility as well as improved stealth to phishing. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains and reducing many of the indicators that security teams have traditionally relied upon for detection,” write the researchers. There is no phishing page to block.
Future phishing detection, say the researchers, will require greater emphasis on identity protection, browser security and behavioral detection – there is no physical page that might trigger an alarm. Techniques should include closer inspection of browser activity involving blob URLs; monitoring OAuth authorization flows for unexpected destinations; and using email security controls that analyze the full click path rather than relying solely on the initial URL.
Related : New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Related : FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
Related : Over 500 Organizations Hit in Years-Long Phishing Campaign
Related : Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations
Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.
More from Kevin Townsend
OpenAI Agents Hijack Another Victim Website
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
Catch Raises $5 Million for AI Executive Assistant With Guardrails
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
OpenLeash Adds a Human Check to Risky AI Agent Actions
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Ivanti Patches Critical Flaws Across Enterprise Security Products
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Chrome 153 Patches Seventh Zero-Day of 2026
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
The Hidden Instructions That Can Hijack AI Agents
Hackers Return $263 Million Stolen From Liquid Network
Virtual Event: Attack Surface Management Summit 2026
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover?
In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
