ZeroHour
Story · 1 source · 1 articlefirst updated ()

Phishing Campaigns Abuse Microsoft Teams and Trusted-Brand Lures: Barracuda Details Blob-URL Sign-In Trick as N0va Kit Targets US and EU Organizations

mediumPhishing & fraudexploited in the wildimportance 58
What's new: First merged summary for this story: two newly documented Teams-based identity theft techniques emerged within a week — Barracuda's 2026-09-10 report of a blob-URL trick that renders fake DocuSign login pages locally inside victims' browsers behind legitimate Microsoft OAuth redirects, and the 2026-09-16 disclosure of the N0va phishing kit, which adds device code phishing and token capture to…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Two newly reported phishing operations abuse Microsoft Teams and DocuSign-style lures to steal identities: Barracuda documents a campaign that renders fake login pages locally via browser blob URLs behind legitimate Microsoft OAuth redirects, while The Hacker…

Barracuda researchers identified an active phishing campaign (reported 2026-09-10) that routes DocuSign-themed emails with calendar invites through a Microsoft OAuth endpoint and crafted redirects into Microsoft Teams, then renders a fake sign-in page via a browser-generated blob URL. Because the page is assembled locally in memory, can register service workers, and runs in a sandboxed iframe, URL-reputation checks largely see legitimate Microsoft domains; the goal is credential theft and account takeover, not a flaw in Teams itself. Separately, The Hacker News (reported 2026-09-16) and ANY.RUN describe the N0va phishing kit, which targets organizations in government, technology, consulting, and healthcare across North America and Europe with lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Victims are guided through legitimate authentication flows, including device code phishing, after which N0va captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish SSO access; compromised identities enable payment fraud, data exposure, and operational disruption. The two reports describe related but distinct operations — neither explicitly links the Barracuda campaign to N0va — but both center on Teams abuse and DocuSign lures, and both steer victims through legitimate Microsoft authentication flows to defeat link- and domain-reputation defenses. Recommended defenses include FIDO2 keys/passkeys, inspection of full redirect paths, and (per ANY.RUN) detection of N0va's characteristic /api/verification/init URL pattern.

  • Barracuda researchers identified an active phishing campaign using DocuSign-themed emails with calendar invites, a Microsoft OAuth endpoint, crafted redirects into Microsoft Teams, and a browser-generated blob URL to render a fake sign-in…
  • The blob-URL phishing page is assembled locally in memory, supports service workers, runs in a sandboxed iframe, and exhibits remotely steered behavior, so URL-reputation filters largely see legitimate Microsoft domains.
  • The Barracuda-documented campaign aims at credential theft and account takeover and does not exploit a flaw in Microsoft Teams itself.
  • The N0va phishing kit (The Hacker News / ANY.RUN, reported 2026-09-16) targets government, technology, consulting, and healthcare organizations across North America and Europe.
  • N0va lures impersonate Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign.
  • N0va attack chain: device code phishing via legitimate authentication flows, capture of access and refresh tokens, abuse of token-exchange or device-registration mechanisms, then SSO access to corporate resources.
  • ANY.RUN tracks N0va via a characteristic /api/verification/init URL query pattern and demonstrates detection in its interactive sandbox.
  • Compromised identities can enable payment fraud, data exposure, and operational disruption.

Coverage timeline

  1. · 7d ago
    Cyber Security News· 48
    Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

    Barracuda details a phishing campaign using Microsoft Teams OAuth redirects and browser blob URLs to render local fake DocuSign login pages for credential theft.