New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
ID: 3b22417b-7ae6-5970-99f6-31381d49584d
STIX ID: report--3b22417b-7ae6-5970-99f6-31381d49584d
Feed Name: cybersecurityNews.com
BlobPhish is a long-running (first observed October 2024) memory-resident credential-phishing campaign that builds phishing pages inside victims' browsers using JavaScript Blob URLs to avoid network, proxy, and file-based detection; it targets Microsoft 365 and major U.S. banks and financial platforms, uses loader pages and WordPress-compromised exfil endpoints, includes multiple IOCs and code-level TTP details, and provides defensive recommendations including sandboxing, threat hunting, and phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
