logo

New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials

ID: 3b22417b-7ae6-5970-99f6-31381d49584d

STIX ID: report--3b22417b-7ae6-5970-99f6-31381d49584d

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Balaji N

...
...

BlobPhish is a long-running (first observed October 2024) memory-resident credential-phishing campaign that builds phishing pages inside victims' browsers using JavaScript Blob URLs to avoid network, proxy, and file-based detection; it targets Microsoft 365 and major U.S. banks and financial platforms, uses loader pages and WordPress-compromised exfil endpoints, includes multiple IOCs and code-level TTP details, and provides defensive recommendations including sandboxing, threat hunting, and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.