New Browser-Based Phishing Campaign Uses Blob URLs for Stealth Attacks

New Browser-Based Phishing Campaign Uses Blob URLs for Stealth Attacks

First seen 9 Sep 2026, 12:14 UTC Securityweekblog.barracuda.com 71.0

Article Content

Browse articles
ThreatCluster

A new phishing campaign analyzed by Barracuda researchers employs blob URLs to generate phishing pages directly within victims' browsers. This method enhances stealth by avoiding traditional phishing site detection, as the phishing content is not hosted on a conventional webpage. Victims receive a DocuSign-themed email with a calendar invitation, which appears legitimate. The attack routes users through trusted Microsoft services, including Teams, making it difficult for security tools to identify malicious activity. The phishing page is dynamically controlled using service workers and iframes, allowing attackers to modify the phishing experience in real-time. This campaign highlights the evolution of phishing tactics, moving away from static sites to more sophisticated browser-based attacks. Security professionals are advised to enhance monitoring of browser activities and OAuth flows to detect such threats.

Key Points: • Attackers use blob URLs to create phishing pages within victims' browsers, enhancing stealth. • The phishing campaign routes victims through trusted Microsoft services, reducing detection risk. • Dynamic control of the phishing experience allows attackers to modify tactics in real-time.

Ask AI about this cluster

Timeline

2026-09-09
New phishing campaign identified
Barracuda researchers reported a phishing campaign using blob URLs to generate malicious pages in browsers, enhancing stealth and evasion of detection.
Securityweek
2026-09-09
Phishing email details revealed
Victims receive a DocuSign-themed email with a calendar invite, which appears legitimate but is part of the phishing strategy.
blog.barracuda.com