logo

Phishing Attack Exploits Blob URLs to Evade Email Security and Detection Systems

ID: 906d66a0-2f5b-5ad6-ad60-2859f0a74b8d

STIX ID: report--906d66a0-2f5b-5ad6-ad60-2859f0a74b8d

Feed Name: Cyber Press

Threat Score
55/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

Cofense Intelligence observed a phishing tactic that leverages browser-generated blob URIs to render phishing credential pages locally in victims' browsers. Attackers use trusted platforms as intermediaries to evade email filters, then serve scripts that create ephemeral blob:http(s) pages containing credential capture forms; because these pages live only in browser memory, they frustrate URL-based detection and forensic retrieval, enabling stealthy exfiltration of user credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.