Barracuda found a phishing campaign that uses genuine Microsoft OAuth and Teams infrastructure to lead victims to a fake login page assembled inside the victim’s browser via a blob URL. The attack begins with a DocuSign-themed email and uses service workers, sandboxed iframes, and hidden command-and-control configuration to dynamically steer victims, making it harder to detect and block. #MicrosoftOAuth #MicrosoftTeams #DocuSign #Barracuda
Keypoints
- The phishing flow begins with a DocuSign-themed email carrying a calendar invite attachment.
- The attack uses genuine Microsoft OAuth and Teams infrastructure to appear trustworthy.
- A crafted redirect sends victims to Teams, which loads content from cdn.bloom[.]io.
- The fake login page is built locally in the browser using a blob URL.
- Barracuda recommends phishing-resistant MFA, deeper link inspection, and monitoring for blob URLs and service workers.
Read More: https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/