New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
ID: 86d2546b-e844-587d-ade9-e3b2f643a085
STIX ID: report--86d2546b-e844-587d-ade9-e3b2f643a085
Feed Name: GBHackers
A Barracuda-reported phishing campaign uses DocuSign-themed lures and legitimate Microsoft services (OAuth and Teams) to deliver credential-harvesting pages assembled as browser blob URLs, meaning the malicious page exists only in the victim's browser session and has no persistent public URL; attackers leverage service workers, sandboxed iframes, and dynamic backend control to evade URL-reputation-based defenses, and defenders are advised to monitor redirect/OAuth flows, blob URL and service-worker activity, analyze full click paths, and deploy phishing-resistant MFA (FIDO2/passkeys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
