news.mlab.sh
Back to the feed
threat-intel

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Medium
Summary

A new phishing campaign bypasses traditional security measures by delivering malicious pages directly within the victim's browser, using blob URLs and trusted processes to avoid detection. This technique significantly reduces the effectiveness of existing security tools and requires a shift in detection strategies towards identity protection and behavioral analysis.

This campaign represents a significant evolution in phishing tactics, moving beyond reliance on static, externally hosted phishing websites. Rather than directing users to a compromised website, attackers now leverage browser technology to render malicious content directly within the victim’s browser window.

It begins with a Docusign-themed email containing a calendar invite, designed to appear as a legitimate business communication. This email then redirects the user to Microsoft Teams, which subsequently loads an external resource hosted on cdn.bloom[.]io. This resource is then converted into a blob URL, allowing the browser to render the phishing page – which exists solely within the browser – without triggering standard security alerts.

Service workers, iframes, and backend controls manage the subsequent phishing workflow and user navigation, creating a complex and automated system. The campaign is not a simple, standalone phishing page; instead, it’s part of a centrally operated and updated platform capable of targeting multiple victims simultaneously.

Researchers at Barracuda highlight that this approach significantly reduces the effectiveness of traditional security tools that rely on identifying malicious websites. Moving forward, detection will need to focus on identity protection, browser security, and behavioral analysis – specifically monitoring browser activity involving blob URLs and scrutinizing OAuth authorization flows.

Read the full article at SecurityWeek