Barracuda research exposes the rise of browser-based phishing

The next phishing page may not live on a website at all. Barracuda’s latest research shows how attackers are shifting the action into the browser, using trusted services and familiar business cues to make detection harder.

author-image
DQChannels Bureau
New Update
Barracuda research exposes the rise of browser-based phishing

Browser-based phishing is changing the familiar phishing playbook. Instead of sending victims to a conventional malicious website, attackers can now generate the phishing page directly inside the browser using blob URLs.

Advertisment

Barracuda researchers found a campaign that uses this approach while routing victims through legitimate Microsoft services, including Microsoft Teams and login.microsoftonline.com. That combination removes several warning signs that security teams and users often rely on when identifying suspicious emails.

Blob URL phishing removes the usual webpage

The key difference is that there may be no traditional phishing website to block. The malicious content exists within a specific browser session, meaning there is no persistent phishing URL for security tools to retrieve, analyse or block in advance.

Once loaded, the page registers a service worker and uses a sandboxed iframe. These browser components help manage requests, navigation and the phishing experience without requiring a conventional website.

Advertisment

The campaign also uses backend infrastructure to dynamically control the workflow. This allows attackers to change destinations and behaviour rather than relying on fixed redirects, adding another layer to these Phishing evasion tactics.

Trusted Microsoft services add another layer

The campaign routes users through legitimate Microsoft infrastructure, making the journey appear more familiar. A calendar invitation included with the email also helps the message resemble routine business communication.

For organisations, this creates a different kind of Email security threat. The issue is not simply whether an incoming URL looks suspicious, but what happens after a user clicks and how the browser behaves.

Advertisment

Barracuda research points to behaviour-based defence

The Barracuda research recommends looking beyond known malicious URLs. Suggested measures include monitoring unusual OAuth authorisation flows and redirect chains, inspecting blob URL activity around login pages, and detecting suspicious service worker registrations.

The guidance also includes phishing-resistant MFA such as FIDO2 security keys and passkeys, along with email security controls that analyse the complete click path.

Read More: 

Alteryx governed business logic is put on show at Gartner Summit 2026

Iris Global and Peritas strengthen enterprise infrastructure push with Dell project

Advertisment

Twilio Report finds a new hurdle for AI customer service

F5 Distributed Cloud Bot Defense rethinks AI agents