Attackers are sending phishing emails that do not lead to a normal fake website, but instead build the fake page inside the victim’s own browser. Barracuda says the campaign starts with a DocuSign-themed email and calendar invite, redirects through Microsoft Teams, then loads content from cdn.bloom.io that is rendered as a blob URL. Service workers, iframes, and hidden command-and-control settings suggest a centrally managed phishing platform rather than a one-off lure.
Why it matters: This makes phishing harder to spot and block because there may be no static phishing page or obvious suspicious domain for defenders to catch. Organizations should review Teams-linked email lures, inspect browser activity involving blob URLs, monitor OAuth sign-in flows, and warn users to be cautious with document-signing and meeting-invite emails.
Kevin Townsend
2026.09.09
100% relevant
This article appears to be the first tracked item establishing this specific browser-rendered phishing technique using Microsoft Teams redirects and blob URLs as the core event.
← Back to all stories