Innovative Email Phishing Attack Uses Blob URLs for Undetectable Threats, ETCISO
Barracuda researchers have published an analysis of an email attack campaign that uses blob URLs to generate a phishing page directly inside a victim’s browser instead of hosting the page on a conventional website.
A blob URL is a temporary browser-generated address that points to content stored locally in memory rather than to content hosted on a website. In the campaign analysed by the researchers, victims are routed through legitimate Microsoft services, including login.microsoftonline.com and Microsoft Teams.
The technique removes some of the indicators traditionally associated with phishing attacks because the phishing content is not hosted on a persistent webpage. As a result, there is no conventional phishing URL for security tools to retrieve, analyse or blocklist in advance.
Abuse of legitimate Microsoft services
The attack chain uses legitimate Microsoft infrastructure to route victims to the phishing content. Because users remain within trusted Microsoft services during parts of the attack, the activity can be harder to distinguish from legitimate authentication or business workflows.
Once the blob-based phishing page loads, it registers a service worker, a browser component that can manage network requests and page behaviour in the background. Part of the workflow also runs inside a sandboxed iframe, an isolated browser window embedded within the page.
The service worker and sandboxed iframe are used to control navigation, manage requests and coordinate the phishing workflow without relying on a conventional phishing website.
Dynamic control of the phishing workflow
The phishing workflow receives instructions from backend infrastructure through browser messaging mechanisms. This allows attackers to modify destinations and behaviour dynamically rather than relying on hardcoded redirects.
The email also contains a calendar invitation file as an attachment. The attachment is not part of the malicious payload but is designed to make the message resemble routine business communication.
Defensive measures
The analysis recommends monitoring OAuth authorisation flows and redirect chains for unusual or unexpected destinations.
Security teams can also monitor browser activity involving blob URLs, particularly when they are used to render login pages or authentication workflows, and detect suspicious service-worker registrations associated with externally sourced content.
Other measures include:
•Using phishing-resistant multifactor authentication methods such as FIDO2 security keys and passkeys.
•Applying email security controls that analyse the full click path rather than relying only on the initial URL.
•Training users to exercise caution with unexpected document-signing requests, even when links appear to use trusted Microsoft infrastructure.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












