Barracuda warns Email phishing attacks are evolving

DQChannels Bureau
DQChannels Bureau
Barracuda warns Email phishing attacks are evolving

Traditional phishing often gives security teams something concrete to chase: a suspicious domain, a malicious URL or a fake login page. A new campaign analysed by Barracuda researchers takes a different route. The phishing page is created directly inside the victim’s browser using blob URLs, leaving no conventional website behind to block.

The bigger concern is not just where the page exists, but how the attack builds trust. Victims are routed through legitimate Microsoft services, including Microsoft Teams and login.microsoftonline.com, reducing some of the warning signs normally associated with Email Phishing attacks.

The Phishing Page Never Really Exists Online

A blob URL points to content stored locally in the browser’s memory rather than to a conventional website. That changes the detection problem. Since the phishing content is created within a specific browser session, there is no persistent phishing URL for security tools to retrieve, analyse or block in advance.

The campaign also relies heavily on browser behaviour. Once the blob-based page loads, it registers a service worker that can manage requests and page behaviour. A sandboxed iframe is also used as part of the workflow, helping coordinate the phishing experience without requiring a traditional website.

Trusted Services Become Part Of The Attack

The use of legitimate Microsoft infrastructure adds another layer. Instead of sending users directly to an obviously suspicious domain, the campaign moves them through services they already recognise.

The workflow is also dynamically controlled through backend infrastructure and browser messaging. This allows attackers to change destinations and behaviour in real time rather than relying on fixed redirects.

Even the email itself is designed to look routine. A calendar invitation file is included as a benign attachment, helping the message resemble normal business communication.

Email Security Needs To Look Beyond URLs

The campaign highlights a wider challenge for phishing detection evasion: blocking known malicious links may not be enough when the malicious experience is created after the user reaches the browser.

Barracuda recommends monitoring unusual OAuth flows and redirect chains, inspecting browser activity involving blob URLs, watching for suspicious service-worker registrations and using phishing-resistant MFA such as FIDO2 security keys and passkeys.

For email security teams, analysing the complete click path rather than only the initial URL becomes particularly important. User awareness also remains relevant, especially around unexpected document-signing requests that appear to use trusted Microsoft infrastructure.

Read More: 

Beyond the SLA: Who owns the business outcome?

The Edge-First Economy: Powering the Last Mile of Digital India

InfoComm India 2026 spotlights Optoma India growth stratergy

InfoComm India 2026 spotlights Optoma India growth stratergy

Latest Stories