ZeroHour
SecurityWeekpublished ()ingested Kevin Townsend
Part of a story covered by 13 sources: “Passkey-themed vishing by Storm-3121/Storm-3032, N0va phishkit, blob-URL phishing, and M365 Direct Send spoofing headline a week of identity attacks” — merged summary and timeline →

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

mediumPhishing & fraud exploited in the wildimportance 52
AI summary · glm-5.3-flash

Barracuda details a phishing campaign that renders pages in-browser via blob URLs, routed through Microsoft Teams and cdn.bloom[.]io to evade detection.

Barracuda researchers analyzed a phishing campaign that generates a blob URL to render the phishing page entirely inside the victim's browser, leaving no static page for scanners to inspect. The chain begins with a Docusign-themed email containing a calendar invite, followed by a crafted redirect through Microsoft Teams to a resource on cdn.bloom[.]io that the browser converts into the blob URL. Service workers, iframes, and a hidden command-and-control configuration indicate the page is part of a centrally managed phishing platform that can be updated and steered across victims. Researchers recommend inspecting blob URL activity, monitoring OAuth authorization flows, and analyzing the full click path in email security controls.

  • Phishing page is rendered as a blob URL inside the victim's browser, leaving no static page to block or scan.
  • Campaign starts with a Docusign-themed email carrying an irrelevant calendar invite to appear legitimate.
  • Crafted redirect routes victims through Microsoft Teams to an external resource hosted on cdn.bloom[.]io.
  • Service workers, iframes, and a hidden C2 config indicate a centrally operated phishing platform.
  • Defenders advised to inspect blob URLs, monitor OAuth flows, and analyze full click paths.

Indicators of compromiseAll →

TypeIndicatorContext
domainbloom.ioTeams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser int
Full article460 words · extracted from securityweek.com · click to collapse

Future phishing campaigns may no longer involve a detectable physical web page.

Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.

The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication.

A crafted redirect routes the user to Microsoft Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser into the blob URL that renders the phishing page existing only within the browser.

Since this process is wrapped up in trusted Microsoft assets, it has all the hallmarks of being trustworthy and is likely to trigger no alarms, providing improved stealth over traditional static external phishing web pages.

The blob-created phishing page exists solely within the victim’s browser. Barracuda’s analysis shows that service workers, iframes and backend controls manage the subsequent phishing workflow and user navigation. A hidden command and control configuration also demonstrates that this automatically constructed phishing page is not a simple stand-alone, but part of a managed platform that can be centrally operated, updated and steered across multiple victims simultaneously.

Advertisement. Scroll to continue reading.

This campaign demonstrates that attackers’ use of blob URL-created phishing pages can add greater flexibility as well as improved stealth to phishing. “This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains and reducing many of the indicators that security teams have traditionally relied upon for detection,” write the researchers. There is no phishing page to block.

Future phishing detection, say the researchers, will require greater emphasis on identity protection, browser security and behavioral detection – there is no physical page that might trigger an alarm. Techniques should include closer inspection of browser activity involving blob URLs; monitoring OAuth authorization flows for unexpected destinations; and using email security controls that analyze the full click path rather than relying solely on the initial URL.

Related: New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Related: FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

Related: Over 500 Organizations Hit in Years-Long Phishing Campaign

Related: Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/