Phish Page Built Inside Your Browser

Help Net Security · High sophistication
Last updated September 10, 2026

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,” reducing the usual warning signs.

How the attack worked

This campaign begins with a DocuSign-themed email carrying a calendar invite as an attachment, designed to look like an ordinary meeting request rather than a document link. The invite is not the actual payload. Instead, it contains a crafted redirect parameter that eventually sends the victim through Microsoft Teams. Teams then loads a resource from an external domain, cdn.bloom[.]io, which results in a phishing page being rendered from a blob URL entirely on the victim's machine, rather than delivered from a standard web server.

Why it succeeded

The technique works because the victim's journey passes through genuine Microsoft OAuth and Teams infrastructure before the fake login page ever appears. Since the phishing content is assembled locally in the browser using a blob URL, there may be no separate phishing website for defenders or filters to identify and block. A service worker and sandboxed iframe give the attacker's backend the ability to send live instructions and adjust what the victim sees in real time, adding further flexibility that static phishing pages lack.

What to watch for

  • An unexpected DocuSign-related meeting invite that arrives as a calendar attachment instead of a normal document link
  • A sign-in flow that bounces through multiple redirects or unusual destinations before requesting credentials
  • Microsoft Teams unexpectedly loading content from an external domain
  • Authentication experiences involving a blob URL rather than a conventional website address
  • New service worker activity appearing during a login session tied to externally loaded content

How to build resistance

Employees, especially those in finance, HR, and executive roles who frequently handle signing requests, should treat unexpected DocuSign or e-signature invites as worth verifying through a separate known channel before interacting with them. Because this attack relies on the appearance of legitimate Microsoft OAuth and Teams infrastructure, users should not assume a sign-in prompt is safe simply because it looks like it belongs to a trusted service. Adopting phishing-resistant multifactor authentication, such as FIDO2 keys or passkeys, reduces the impact if credentials are still captured. Security operations and identity teams should also shift detection efforts toward behavioral signals, including blob URL activity in authentication contexts and service worker registrations tied to externally loaded content, since this style of attack removes many of the domain-based indicators that traditional phishing detection has relied on.

Key findings

  • Victims are routed through legitimate Microsoft OAuth and Microsoft Teams infrastructure before seeing the fake login experience.
  • The phishing content is rendered locally using a browser “blob URL,” so there may be no obvious phishing website to block.
  • The initial lure is a DocuSign-themed email with a calendar invite attachment designed to look like a normal meeting request.
  • Microsoft Teams loads a resource from an external domain (cdn.bloom[.]io), which leads to the phishing page being rendered via a blob URL.
  • The phishing page uses a service worker and a sandboxed iframe, enabling the attacker backend to send live instructions and change what the victim sees.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT/Identity & Access Management, Security Operations.
  • Affected industries: Multiple industries (any organization using Microsoft 365/OAuth and Teams).
  • Attack channels: email, website.
  • Impersonated: DocuSign, Microsoft (OAuth/Teams sign-in experience).

Red flags to watch for

  • Unexpected DocuSign-related meeting invite rather than a normal document link
  • Sign-in flow includes unusual redirect steps or destinations
  • Login prompt appears after bouncing through Microsoft services in an unexpected way
  • Teams unexpectedly loads content from an external domain
  • Authentication experience involves a blob URL (browser-generated local URL) rather than a normal website
  • Browser shows new service worker activity tied to externally loaded content during login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a blob URL phishing attack?

It is a technique where the phishing login page is assembled locally inside the victim's browser using a temporary blob URL instead of being hosted on a separate suspicious website, which removes many traditional warning signs.

How does the DocuSign calendar invite fit into this attack?

The campaign starts with a DocuSign-themed email containing a calendar invite attachment that looks like a normal meeting request, but its real purpose is to route the victim toward a crafted redirect and eventually a fake Microsoft login.

Why does this attack bypass typical phishing defenses?

Because victims are routed through genuine Microsoft OAuth and Teams infrastructure and the final phishing page is rendered locally via a blob URL, there is often no obvious malicious domain or website for security tools to flag.

What can security teams do to detect this kind of attack?

Teams are advised to monitor OAuth authorization flows and redirect chains for unexpected destinations, inspect blob URL activity during login, and flag service worker registrations tied to externally loaded content.

Read the video transcript

You get an email: “Meeting invitation: DocuSign, Review and sign document.” Looks like a normal calendar invite, right? You open it, click through, and it even bounces you through real Microsoft OAuth and a Teams page. So your guard drops… but that’s the trick. Behind the scenes, Teams quietly loads cdn.bloom.io, then your browser builds a fake Microsoft login inside itself using a blob URL, no obvious phishing site, just a perfect-looking sign-in box waiting for your password. If you get an unexpected DocuSign meeting invite that sends you through odd Microsoft redirects, stop and verify it with the sender over chat or phone before you sign in.

Similar attacks

Blob URL Phish Hides Page Inside Your Browser

Blob URL Phish Hides Page Inside Your Browser

Barracuda observed a real phishing campaign that avoids hosting a traditional fake website. Instead, victims are led through Microsoft Teams to load a resource that their browser converts into a “blob URL,” rendering the phishing page only inside the victim’s browser, making it harder for scanners…

September 9, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026