Blob URL Phish Hides Page Inside Your Browser

Security Week Feed · High sophistication
Last updated September 9, 2026

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners and blocklists to catch.

Key findings

  • Attack starts with a DocuSign-themed email containing an attached calendar invite to appear legitimate.
  • A crafted redirect sends the victim to Microsoft Teams, which loads an external resource hosted on cdn.bloom[.]io.
  • The victim’s browser converts that resource into a blob URL, so the phishing page exists only inside the browser rather than on a normal web page.
  • The phishing kit uses service workers/iframes and hidden command-and-control configuration, indicating a centrally managed platform.
  • Because the flow is wrapped in trusted Microsoft assets, it is less likely to trigger traditional URL/domain-based detections.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, HR, Sales, IT/Helpdesk.
  • Affected industries: Cross-industry (any organization using Microsoft 365/Teams and receiving e-signature documents).
  • Attack channels: email, website.
  • Impersonated: DocuSign (brand-themed email).

Awareness takeaways

  • Treat unexpected DocuSign-style requests as suspicious, especially if they include odd extras like calendar invites, and verify with the sender via a known-good channel.
  • Be cautious of links that route you through trusted services (like Microsoft Teams) before showing content; attackers may use trusted platforms to hide where you’re really going.
  • If a sign-in page appears unexpectedly during a document/viewing workflow, stop and report it, this campaign is designed so there may be “no phishing page to block.”

Red flags to watch for

  • Unexpected calendar invite attached to a document-signing email
  • Being routed through Microsoft Teams for a document-signing flow you didn’t initiate
  • Unusual link destinations/redirects before reaching any real document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you get a DocuSign email with a calendar invite attached, and it all opens inside Microsoft Teams. You click, get bounced through a crafted redirect into Teams, which quietly loads cdn.bloom.io. Your browser turns that into a blob URL, so the phishing page lives only inside your browser, there’s almost nothing for filters to block. Here’s the trick: it looks like a normal sign-in, wrapped in trusted Microsoft assets, but you got there from an unexpected DocuSign email, through Teams, and now a blob URL login pops up out of nowhere. If a DocuSign request sends you through Teams and then a surprise login or blob URL appears, stop, don’t sign in. Report it to security right away.

Similar attacks

Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026