Phishers Use Microsoft Teams and Blob URLs to Bypass Detection
A new phishing campaign has emerged, using a sophisticated technique to evade detection and steal victims' credentials. The attackers use browser-generated blob URLs to assemble fake login pages inside the victim's browser, making it harder for security tools to inspect before they appear.
The campaign starts with an email carrying a DocuSign-themed calendar invitation. The link initially reaches a Microsoft OAuth endpoint and then follows a crafted redirect into Microsoft Teams.
Barracuda researchers identified the campaign, which replaces hosted phishing sites with pages created inside the browser. This technique adds pressure to phishing defenses already strained by attacks abusing collaboration tools.