Microsoft Teams blob-URL phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A phishing campaign now renders lure pages as blob URLs inside victims’ browsers, reducing static-page detection and increasing attacker control over delivery. The chain uses a Docusign-themed email, an attached calendar invite, and a redirect through Microsoft Teams to load content from cdn.bloom[.]io. The browser then turns that content into the phishing page, while service workers, iframes, and backend controls manage navigation. The design removes the usual external page footprint and shifts detection toward browser activity and click-path behavior.
Related Happenings
LogoKit real-time per-victim phishing campaign
Campaign
H score35
First: 29.07.2026 19:00
Last: 29.07.2026 19:00
Sources 1
About this happening:
The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
LogoKit real-time per-victim phishing campaign
CampaignAbout this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
OpenAI ChatGPT renderer Markdown link/image phishing security flaw
Vulnerability
H score16
First: 29.05.2026 21:07
Last: 29.05.2026 21:07
Sources 1
About this happening:
ChatGPT has a response-renderer vulnerability that turns summarized third-party pages into live phishing links and auto-fetched attacker-hosted images inside the t...
OpenAI ChatGPT renderer Markdown link/image phishing security flaw
VulnerabilityAbout this happening: ChatGPT has a response-renderer vulnerability that turns summarized third-party pages into live phishing links and auto-fetched attacker-hosted images inside the t...
Timeline
-
09.09.2026 13:00 2 articles · 2h ago
Barracuda analyzes browser-rendered blob URL phishing campaign
Technical Analysis UpdateBarracuda analyzes a phishing campaign that uses a Docusign-themed email with an attached calendar invite, a crafted redirect through Microsoft Teams, and content from cdn.bloom[.]io to generate a blob URL that renders the phishing page inside the victim’s own browser. The workflow uses service workers, iframes, and backend controls to manage navigation and can be centrally operated across multiple victims, reducing the static web-page footprint that traditional scanners look for.
Show sources
- New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser — www.securityweek.com — 09.09.2026 13:00
- New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser — www.securityweek.com — 09.09.2026 13:00