DocuSign Phish Uses “Blob” Pages in Your Browser

IT Pro Security · High sophistication
Last updated September 10, 2026

Researchers described a real phishing campaign where victims click through legitimate Microsoft services and end up on a fake login page that is generated inside their own browser. The phishing page uses a temporary “blob URL” (not a normal website) and can disappear after the session, making it harder for security tools to block using traditional URL lists.

Key findings

  • The lure is a DocuSign-themed phishing email that includes a calendar invite attachment.
  • Victims are routed through legitimate Microsoft services (Microsoft OAuth and Microsoft Teams) to look trustworthy.
  • The phishing page is rendered locally as a browser “blob URL,” leaving no normal phishing site to blocklist.
  • The page registers a service worker and uses a sandboxed iframe to control the phishing flow and evade static URL-based detection.
  • The attackers can change destinations/behavior in real time via backend instructions sent through browser messaging.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive assistants, Finance, Sales, IT helpdesk/service desk, Security operations.
  • Affected industries: Cross-industry (any organization using Microsoft 365/Teams).
  • Attack channels: email.
  • Impersonated: DocuSign.

Awareness takeaways

  • Treat unexpected calendar invites and document-signature emails as high-risk and verify with the sender via a known channel before clicking.
  • Don’t assume a link is safe just because it routes through a trusted brand (like Microsoft); attackers can abuse trusted services to hide the real destination.
  • Be cautious if a login experience behaves strangely (multiple redirects, unusual address formats, or the page seems to ‘appear’ and then disappear). Stop and report it.
  • Security teams should complement email/URL scanning with endpoint/browser behavior monitoring, since some phishing pages won’t have a blockable URL.

Red flags to watch for

  • Unexpected calendar invite attached to a DocuSign-themed email
  • Login flow that bounces through Microsoft services but ends with an unusual, temporary page (blob URL) asking for credentials
  • Unusual behavior immediately after interacting with the calendar invite (unexpected redirects)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “DocuSign: Signature requested, meeting invite attached.” Looks routine, calendar invite and all. You open the invite, click the link, and it bounces through real Microsoft OAuth and Teams pages. So your brain goes, “Okay, this is safe.” Here’s the trick: Teams quietly loads content from cdn.bloom.io, your browser turns it into a temporary blob URL, and a fake Microsoft 365 login appears that can vanish without leaving a normal phishing site to block. If a DocuSign email comes with a surprise calendar invite or a login flow that suddenly flips to a weird blob URL, stop. Don’t sign in, report it to Security immediately.

Similar attacks

Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Blob URL Phish Hides Page Inside Your Browser

Blob URL Phish Hides Page Inside Your Browser

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners…

September 9, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
DocuSign-Themed M365 AiTM Phish Uses Redirect Chain

DocuSign-Themed M365 AiTM Phish Uses Redirect Chain

The recap describes a real Microsoft 365 phishing campaign using DocuSign-themed emails that push victims through multiple redirects to a fake sign-in page. The goal is to steal session tokens (so attackers can log in even if a password changes) and also perform “device code” style sign-in abuse.…

September 7, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026