DocuSign-Themed Phishing Campaign Uses Microsoft Teams Redirects and Browser Blob URLs to Evade URL Detection
Barracuda researchers detailed a credential-harvesting campaign that sends DocuSign-themed emails with calendar invites, routes victims through legitimate Microsoft OAuth endpoints and Teams, and renders the fake sign-in page as a browser blob URL — leaving…
Barracuda researchers report an active phishing campaign that begins with a DocuSign-themed email containing a calendar invitation. The chain routes victims through a legitimate Microsoft OAuth endpoint and crafted redirect parameters into Microsoft Teams, which then loads external content from cdn.bloom[.]io. The browser renders this content as a blob URL — a session-only address assembled locally in memory with no persistent public URL — so URL-reputation checks and link filters largely see only legitimate Microsoft domains. The locally generated page registers a service worker, runs inside a sandboxed iframe, and is dynamically steered by backend infrastructure, indicating a centrally managed phishing platform that can adjust the flow per victim. The goal is credential theft and account takeover; the reports note this is an abuse of legitimate flows, not a flaw in Teams itself. Barracuda recommends phishing-resistant MFA such as FIDO2 keys and passkeys, monitoring of OAuth flows and full redirect chains, and Teams malicious URL protection. The two reports agree on the attack chain and mitigations; only GBHackers specifies the cdn.bloom[.]io domain.
- Campaign starts with DocuSign-themed phishing emails containing calendar invitations.
- Attack chain routes through a legitimate Microsoft OAuth endpoint and crafted redirects into Microsoft Teams before loading content from cdn.bloom[.]io.
- The phishing page is rendered as a browser blob URL — session-only and held in local memory with no persistent public URL to crawl, categorize, or blocklist.
- The page registers a service worker, runs in a sandboxed iframe, and is dynamically steered by backend infrastructure, indicating a centrally managed phishing platform.
- The objective is credential theft and account takeover; this is an abuse of legitimate Microsoft flows, not a vulnerability in Teams.
- Recommended defenses: phishing-resistant MFA (FIDO2 keys, passkeys), monitoring OAuth flows and full redirect/click paths, and Teams malicious URL protection.
Coverage timelineoldest first · each row is one article
- · 6d agoNew Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
GBHackers· 48
Barracuda detailed a DocuSign-themed phishing campaign that renders credential-harvesting pages as browser blob URLs, evading URL reputation and blocklist defenses.
- · 6d agoHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News· 48
Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.