Phishing Attack Exploits Blob URLs to Evade Email Security and Detection Systems
ID: 906d66a0-2f5b-5ad6-ad60-2859f0a74b8d
STIX ID: report--906d66a0-2f5b-5ad6-ad60-2859f0a74b8d
Feed Name: Cyber Press
Threat Score
Cofense Intelligence observed a phishing tactic that leverages browser-generated blob URIs to render phishing credential pages locally in victims' browsers. Attackers use trusted platforms as intermediaries to evade email filters, then serve scripts that create ephemeral blob:http(s) pages containing credential capture forms; because these pages live only in browser memory, they frustrate URL-based detection and forensic retrieval, enabling stealthy exfiltration of user credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
