Phishing campaign uses Microsoft Teams and browser blob URLs to create login pages inside victims’ browsers

Attackers are sending phishing emails that do not lead to a normal fake website, but instead build the fake page inside the victim’s own browser. Barracuda says the campaign starts with a DocuSign-themed email and calendar invite, redirects through Microsoft Teams, then loads content from cdn.bloom.io that is rendered as a blob URL. Service workers, iframes, and hidden command-and-control settings suggest a centrally managed phishing platform rather than a one-off lure.
Why it matters: This makes phishing harder to spot and block because there may be no static phishing page or obvious suspicious domain for defenders to catch. Organizations should review Teams-linked email lures, inspect browser activity involving blob URLs, monitor OAuth sign-in flows, and warn users to be cautious with document-signing and meeting-invite emails.

Sources

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Kevin Townsend 2026.09.09 100% relevant
This article appears to be the first tracked item establishing this specific browser-rendered phishing technique using Microsoft Teams redirects and blob URLs as the core event.
← Back to all stories