Skip to content
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

Gbhackers Mayura Kathir September 10, 2026

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser.

Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain.

A blob URL is a temporary browser address that references content held in local memory rather than a remotely hosted webpage.

As a result, the phishing page has no persistent public URL and exists only within the active browser session.

The campaign begins with a DocuSign-themed email designed to resemble a routine business document-signing request.

The message includes a calendar invitation attachment, which is not itself the payload but helps establish legitimacy by making the lure look like a normal meeting or workflow notification.

Victims who interact with the link are routed through legitimate Microsoft services, including Microsoft OAuth endpoints and Microsoft Teams.

Barracuda Researchers said that , the operation uses browser-generated blob URLs to render a fake authentication page locally, leaving defenders with no conventional phishing site to crawl, categorize, or blocklist in advance.

Phishing Attack Uses Blob URLs

A crafted redirect parameter ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal external webpage, the browser converts it into a blob URL and renders the phishing interface locally.

That sequence creates a dangerous trust signal. Users may see familiar Microsoft domains, branding, and behavior during the early stages of the attack, reducing the obvious indicators commonly associated with credential phishing.

Automated scanners can face a similar problem: the initial link path may appear benign or lead through reputable Microsoft-hosted infrastructure before the browser-side page is generated.

Once the locally generated phishing page loads, it registers a service worker and runs part of its workflow inside a sandboxed iframe.

Service workers can manage network activity and influence page behavior in the background, while sandboxed iframes can isolate and coordinate portions of the malicious interface.

The attack is also dynamically controlled through backend infrastructure and browser messaging mechanisms. This means operators do not need to rely on fixed redirects or hardcoded destinations.

They can alter the phishing flow, change targets, update content, and steer victims in real time without rebuilding or rehosting a static credential-harvesting page.

The architecture suggests a centrally managed phishing platform rather than a one-off lure.

Hidden command-and-control configuration enables attackers to coordinate campaigns across multiple victims while minimizing the persistent artifacts such as domains, page source, and stable URLs that traditional security tools use for detection and takedown.

The campaign highlights why URL reputation alone is increasingly insufficient for phishing defense.

Security teams should examine the complete interaction chain, particularly where trusted cloud services , redirects, browser APIs, and identity prompts intersect.

Barracuda recommends monitoring OAuth authorization flows and redirect chains for unusual destinations, inspecting blob URL use in login and authentication contexts, and identifying suspicious service-worker registrations tied to externally sourced content.

Organizations should also deploy phishing-resistant MFA, including FIDO2 security keys and passkeys, to reduce the value of stolen passwords.

Email defenses should analyze the entire click path rather than only the first URL, while user-awareness programs should emphasize that a familiar Microsoft domain or a DocuSign-themed invitation does not guarantee that an authentication request is legitimate.

Microsoft Teams administrators can also enable malicious URL protection, which scans URLs shared in Teams messages against threat-intelligence sources and displays warnings for known harmful links.

While it will not eliminate browser-resident phishing by itself, it adds a useful control at an earlier point in the attack chain.

★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026 .

Artificial Intelligence

Cyber security Course

Cyber Security Resources

Cybersecurity

Information Gathering

Information Security Risks

OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing

12 Best Patch Management Software Compared (2026): Features & Pricing

The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced

The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced

Extracted Entities