Back to Feed
Threat IntelligenceSep 9, 2026

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

New phishing attack uses blob URLs to render malicious pages inside the victim's browser.

Summary

Attackers are employing a novel phishing technique that generates malicious pages directly within the victim's browser using blob URLs, bypassing traditional detection methods. This method leverages trusted Microsoft services and a multi-stage redirect, starting with a DocuSign-themed email and calendar invite, to obscure the attack and deliver the phishing content. The dynamically generated pages are managed by a backend platform, making them highly flexible and difficult for security scanners to identify.

Full text

Future phishing campaigns may no longer involve a detectable physical web page. Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page. The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication. A crafted redirect routes the user to Microsoft Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser into the blob URL that renders the phishing page existing only within the browser. Since this process is wrapped up in trusted Microsoft assets, it has all the hallmarks of being trustworthy and is likely to trigger no alarms, providing improved stealth over traditional static external phishing web pages. The blob-created phishing page exists solely within the victim’s browser. Barracuda’s analysis shows that service workers, iframes and backend controls manage the subsequent phishing workflow and user navigation. A hidden command and control configuration also demonstrates that this automatically constructed phishing page is not a simple stand-alone, but part of a managed platform that can be centrally operated, updated and steered across multiple victims simultaneously.Advertisement. Scroll to continue reading. This campaign demonstrates that attackers’ use of blob URL-created phishing pages can add greater flexibility as well as improved stealth to phishing. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains and reducing many of the indicators that security teams have traditionally relied upon for detection,” write the researchers. There is no phishing page to block. Future phishing detection, say the researchers, will require greater emphasis on identity protection, browser security and behavioral detection – there is no physical page that might trigger an alarm. Techniques should include closer inspection of browser activity involving blob URLs; monitoring OAuth authorization flows for unexpected destinations; and using email security controls that analyze the full click path rather than relying solely on the initial URL. Related: New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Related: FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service Related: Over 500 Organizations Hit in Years-Long Phishing Campaign Related: Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend OpenAI Agents Hijack Another Victim WebsiteOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersCatch Raises $5 Million for AI Executive Assistant With GuardrailsCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionOpenLeash Adds a Human Check to Risky AI Agent ActionsUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureSevii Targets AI-Speed Attacks With Preemptive Autonomous Defense Latest News Chrome 153 Patches Seventh Zero-Day of 2026Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayThe Hidden Instructions That Can Hijack AI AgentsHackers Return $263 Million Stolen From Liquid NetworkCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • domain — cdn.bloom[.]io

Entities

Microsoft Teams (product)Microsoft (vendor)DocuSign (product)blob URL (technology)service worker (technology)iframe (technology)