logo

BlobPhish: The Phantom Phishing Campaign Hiding in Browser Memory

ID: 1d4852b8-e056-57d4-9d00-024b52bb612c

STIX ID: report--1d4852b8-e056-57d4-9d00-024b52bb612c

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
72/100

Date Published: 2026-04-16

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

BlobPhish is an active, ongoing credential-phishing campaign (first observed Oct 2024) that constructs phishing pages in-browser by decoding a Base64 payload into a Blob object and navigating to a blob:https:// URL to remain memory-resident and evade URL reputation, proxies, and disk-based detection. The campaign targets Microsoft 365 and major U.S. financial services, reuses exfiltration endpoints (res.php, tele.php, panel.php) hosted on compromised WordPress sites, includes a YARA rule and IOCs for detection, and poses high business risk via account takeover, BEC, and potential lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.