
Browser-based phishing is changing the familiar phishing playbook. Instead of sending victims to a conventional malicious website, attackers can now generate the phishing page directly inside the browser using blob URLs.
Barracuda researchers found a campaign that uses this approach while routing victims through legitimate Microsoft services, including Microsoft Teams and login.microsoftonline.com. That combination removes several warning signs that security teams and users often rely on when identifying suspicious emails.
Blob URL phishing removes the usual webpage
The key difference is that there may be no traditional phishing website to block. The malicious content exists within a specific browser session, meaning there is no persistent phishing URL for security tools to retrieve, analyse or block in advance.
Once loaded, the page registers a service worker and uses a sandboxed iframe. These browser components help manage requests, navigation and the phishing experience without requiring a conventional website.
The campaign also uses backend infrastructure to dynamically control the workflow. This allows attackers to change destinations and behaviour rather than relying on fixed redirects, adding another layer to these Phishing evasion tactics.
Trusted Microsoft services add another layer
The campaign routes users through legitimate Microsoft infrastructure, making the journey appear more familiar. A calendar invitation included with the email also helps the message resemble routine business communication.
For organisations, this creates a different kind of Email security threat. The issue is not simply whether an incoming URL looks suspicious, but what happens after a user clicks and how the browser behaves.
Barracuda research points to behaviour-based defence
The Barracuda research recommends looking beyond known malicious URLs. Suggested measures include monitoring unusual OAuth authorisation flows and redirect chains, inspecting blob URL activity around login pages, and detecting suspicious service worker registrations.
The guidance also includes phishing-resistant MFA such as FIDO2 security keys and passkeys, along with email security controls that analyse the complete click path.
Read More:
Alteryx governed business logic is put on show at Gartner Summit 2026
Iris Global and Peritas strengthen enterprise infrastructure push with Dell project
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us