logo

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

ID: 6399aaac-1ebf-5f29-a87f-1627546b37bf

STIX ID: report--6399aaac-1ebf-5f29-a87f-1627546b37bf

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Tushar Subhra Dutta

...
...

Researchers observed a phishing campaign that leverages Microsoft OAuth redirects and Microsoft Teams to load attacker-supplied resources which the browser converts into blob URLs, rendering convincing fake sign-in pages locally to evade URL-based filters; the primary objective is credential theft and account takeover. The report describes the attack flow, browser features abused (blob URLs, service workers, sandboxed iframes), offers detection and mitigation guidance (inspect full click paths, preserve browser logs, adopt FIDO2/passkeys), and lists two defanged IoCs: cdn.bloom.io and login.microsoftonline.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.