Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Innovative Email Phishing Attack Uses Blob URLs for Undetectable Threats, ETCISO

Innovative Email Phishing Attack Uses Blob URLs for Undetectable Threats, ETCISO

Innovative Email Phishing Attack Uses Blob URLs for Undetectable Threats, ETCISO

Barracuda researchers have published an analysis of an email attack campaign that uses blob URLs to generate a phishing page directly inside a victim’s browser instead of hosting the page on a conventional website.

A blob URL is a temporary browser-generated address that points to content stored locally in memory rather than to content hosted on a website. In the campaign analysed by the researchers, victims are routed through legitimate Microsoft services, including login.microsoftonline.com and Microsoft Teams.

The technique removes some of the indicators traditionally associated with phishing attacks because the phishing content is not hosted on a persistent webpage. As a result, there is no conventional phishing URL for security tools to retrieve, analyse or blocklist in advance.

Abuse of legitimate Microsoft services

The attack chain uses legitimate Microsoft infrastructure to route victims to the phishing content. Because users remain within trusted Microsoft services during parts of the attack, the activity can be harder to distinguish from legitimate authentication or business workflows.

Once the blob-based phishing page loads, it registers a service worker, a browser component that can manage network requests and page behaviour in the background. Part of the workflow also runs inside a sandboxed iframe, an isolated browser window embedded within the page.

The service worker and sandboxed iframe are used to control navigation, manage requests and coordinate the phishing workflow without relying on a conventional phishing website.

Dynamic control of the phishing workflow

The phishing workflow receives instructions from backend infrastructure through browser messaging mechanisms. This allows attackers to modify destinations and behaviour dynamically rather than relying on hardcoded redirects.

The email also contains a calendar invitation file as an attachment. The attachment is not part of the malicious payload but is designed to make the message resemble routine business communication.

Defensive measures

The analysis recommends monitoring OAuth authorisation flows and redirect chains for unusual or unexpected destinations.

Security teams can also monitor browser activity involving blob URLs, particularly when they are used to render login pages or authentication workflows, and detect suspicious service-worker registrations associated with externally sourced content.

Other measures include:

•Using phishing-resistant multifactor authentication methods such as FIDO2 security keys and passkeys.

•Applying email security controls that analyse the full click path rather than relying only on the initial URL.

•Training users to exercise caution with unexpected document-signing requests, even when links appear to use trusted Microsoft infrastructure.

  • Published On Sep 25, 2026 at 08:00 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket