ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

DocuSign-Themed Phishing Campaign Uses Microsoft Teams Redirects and Browser Blob URLs to Evade URL Detection

mediumPhishing & fraudexploited in the wildimportance 48
What's new: First merged summary for this story; no prior version. Both source reports (GBHackers and Cyber Security News, both dated 2026-09-10) describe the same Barracuda finding and agree on the attack chain and mitigations; only GBHackers names the cdn.bloom[.]io domain hosting the external content.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Barracuda researchers detailed a credential-harvesting campaign that sends DocuSign-themed emails with calendar invites, routes victims through legitimate Microsoft OAuth endpoints and Teams, and renders the fake sign-in page as a browser blob URL — leaving…

Barracuda researchers report an active phishing campaign that begins with a DocuSign-themed email containing a calendar invitation. The chain routes victims through a legitimate Microsoft OAuth endpoint and crafted redirect parameters into Microsoft Teams, which then loads external content from cdn.bloom[.]io. The browser renders this content as a blob URL — a session-only address assembled locally in memory with no persistent public URL — so URL-reputation checks and link filters largely see only legitimate Microsoft domains. The locally generated page registers a service worker, runs inside a sandboxed iframe, and is dynamically steered by backend infrastructure, indicating a centrally managed phishing platform that can adjust the flow per victim. The goal is credential theft and account takeover; the reports note this is an abuse of legitimate flows, not a flaw in Teams itself. Barracuda recommends phishing-resistant MFA such as FIDO2 keys and passkeys, monitoring of OAuth flows and full redirect chains, and Teams malicious URL protection. The two reports agree on the attack chain and mitigations; only GBHackers specifies the cdn.bloom[.]io domain.

  • Campaign starts with DocuSign-themed phishing emails containing calendar invitations.
  • Attack chain routes through a legitimate Microsoft OAuth endpoint and crafted redirects into Microsoft Teams before loading content from cdn.bloom[.]io.
  • The phishing page is rendered as a browser blob URL — session-only and held in local memory with no persistent public URL to crawl, categorize, or blocklist.
  • The page registers a service worker, runs in a sandboxed iframe, and is dynamically steered by backend infrastructure, indicating a centrally managed phishing platform.
  • The objective is credential theft and account takeover; this is an abuse of legitimate Microsoft flows, not a vulnerability in Teams.
  • Recommended defenses: phishing-resistant MFA (FIDO2 keys, passkeys), monitoring OAuth flows and full redirect/click paths, and Teams malicious URL protection.

Coverage timeline

  1. · 6d ago
    GBHackers· 48
    New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

    Barracuda detailed a DocuSign-themed phishing campaign that renders credential-harvesting pages as browser blob URLs, evading URL reputation and blocklist defenses.

  2. · 6d ago
    Cyber Security News· 48
    Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

    Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.