Cybercriminals are building phishing pages that exist only inside victims’ browsers

Cybercriminals are building phishing pages that exist only inside victims’ browsers
Barracuda found a phishing campaign that uses genuine Microsoft OAuth and Teams infrastructure to lead victims to a fake login page assembled inside the victim’s browser via a blob URL. The attack begins with a DocuSign-themed email and uses service workers, sandboxed iframes, and hidden command-and-control configuration to dynamically steer victims, making it harder to detect and block. #MicrosoftOAuth #MicrosoftTeams #DocuSign #Barracuda

Keypoints

  • The phishing flow begins with a DocuSign-themed email carrying a calendar invite attachment.
  • The attack uses genuine Microsoft OAuth and Teams infrastructure to appear trustworthy.
  • A crafted redirect sends victims to Teams, which loads content from cdn.bloom[.]io.
  • The fake login page is built locally in the browser using a blob URL.
  • Barracuda recommends phishing-resistant MFA, deeper link inspection, and monitoring for blob URLs and service workers.

Read More: https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/