Instead of sending victims to a hosted credential-harvesting page, the attackers generate the phishing page directly inside the victim’s browser using a blob URL This article explores embedded phishing source. . Security tools cannot easily crawl, analyze, categorize, or blocklist it before a victim opens the link.

The campaign also uses legitimate Microsoft services, including Microsoft OAuth redirects and Microsoft Teams domains, to make the attack chain appear more trustworthy. Crafted Redirects Facilitate Browser-Embedded Phishing (Source: Barracuda) Attackers exploit a manipulated redirect parameter to trick victims into navigating through Microsoft’s authentication process and then to Microsoft Teams. Teams then retrieves an external resource from cdn.bloom[. ]io.

A blob URL is created by the browser and points to data stored locally within the user's browser session, rather than being accessible through a stable, publicly visible URL that defenders can monitor or block. The sandboxed iframe introduces an additional layer of separation and control, allowing parts of the phishing process to run within an embedded browser frame. This enables operators to dynamically change the victim's path, update phishing content, or redirect users to different login prompts in real time, as Barracuda noted.

This allows attackers to swiftly modify campaigns across various targets without needing to create a new phishing site each time.