Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages
September 11, 2026
Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers
September 11, 2026
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Home/Threats/Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages
Threats

Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages

Key Takeaways A novel phishing campaign is circumventing traditional security measures by generating malicious login pages directly within victims’ browsers using “blob URLs.” The...

Jennifer sherman
Jennifer sherman
September 11, 2026 5 Min Read
2 0

Key Takeaways

  • A novel phishing campaign is circumventing traditional security measures by generating malicious login pages directly within victims’ browsers using “blob URLs.”
  • The attack chain leverages legitimate Microsoft OAuth endpoints and redirects through Microsoft Teams, making the initial stages appear trustworthy.
  • Instead of hosting phishing sites, attackers use browser-generated blob URLs to create the fake login interface in local memory, making it harder for security tools to detect proactively.
  • The primary objective is credential theft and account takeover, exploiting user trust in familiar brands and seemingly secure Microsoft infrastructure.

Attackers Exploit Microsoft Teams and Blob URLs for In-Browser Phishing

A sophisticated new phishing operation is sidestepping conventional email and web security by constructing fake login pages directly inside victims’ web browsers. This innovative approach utilizes browser-generated “blob URLs” to render the malicious content in local memory, significantly reducing the observable footprint that security solutions typically scrutinize before a deceptive page appears.

Table Of Content

  • Key Takeaways
  • Attackers Exploit Microsoft Teams and Blob URLs for In-Browser Phishing
  • The Role of Blob URLs and Microsoft Teams in the Attack Chain
  • Detection Must Follow Behavior
  • What You Should Do

The attack initiates with a DocuSign-themed email containing a calendar invitation. Clicking the embedded link first directs the user to a legitimate Microsoft OAuth endpoint. Subsequently, a specially crafted redirect then guides the user’s session into Microsoft Teams. This trusted pathway is crucial, as it lends an air of legitimacy to what might otherwise be a suspicious document request, effectively masking the point at which harmful content is introduced into the browsing session.

Researchers at Barracuda were instrumental in identifying this campaign. They highlighted that the technique entirely replaces the need for an attacker-hosted phishing site, opting instead for a page assembled dynamically within the user’s browser. This method intensifies the challenge for existing phishing defenses, which are already struggling with the pervasive abuse of collaboration platforms like Microsoft Teams in recent phishing activities. The immediate threat posed by this campaign is the theft of user credentials and subsequent account takeover, rather than a direct vulnerability within Teams itself.

Should a user encounter a highly convincing sign-in prompt, they may inadvertently submit their corporate credentials or approve a subsequent request. This action could grant attackers unauthorized access to critical business services linked to that identity, including email accounts and cloud-based files. As Barracuda said in a report, this workflow effectively diminishes the warning indicators that both users and automated scanners rely upon. The campaign underscores that the presence of familiar branding and seemingly safe web addresses alone cannot guarantee the legitimacy of a login page.

The Role of Blob URLs and Microsoft Teams in the Attack Chain

A blob URL serves as a temporary, browser-generated address for data held within an active browsing session. In this phishing scheme, Microsoft Teams loads an external resource, which the browser then converts into a blob URL. This URL is used to display the phishing interface directly and locally to the user. Crucially, the malicious page is not hosted on an external server controlled by the attacker, preventing security filters from pre-assessing and blocking the destination.

This distinction is vital because many email filtering systems primarily inspect the initial destination of a link. When the visible click path involves legitimate Microsoft services, the early stages of the attack appear benign. The deceptive login interface only materializes after the full redirect sequence has completed, a tactic observed in other blob URL phishing techniques reported this year. Barracuda researchers noted that the dynamically generated page can also register a service worker and execute activities within a sandboxed iframe.

These browser functionalities enable the malicious page to manage requests and navigation within the active session. Furthermore, threat actors can transmit instructions from their remote infrastructure, allowing them to modify destinations or behaviors without needing to reconstruct every phishing lure. The calendar invitation itself is not the malicious payload but serves as a critical social engineering component, making the email resemble a routine meeting request that an employee might anticipate. This exploitation of business context mirrors a broader trend of phishing attacks that abuse OAuth redirects to obscure the true destination of a fake sign-in experience.

Detection Must Follow Behavior

To combat these advanced phishing tactics, security teams must move beyond inspecting initial URLs and instead analyze the entire click path. Red flags include unusual OAuth authorization requests, unexpected redirect destinations, and the use of blob URLs to display sign-in forms. Browser telemetry can also provide valuable insights, revealing suspicious service-worker registrations linked to externally supplied content. Organizations can significantly reduce their exposure by implementing phishing-resistant authentication methods, such as FIDO2 security keys and passkeys, in conjunction with robust identity controls. These measures render a stolen password considerably less effective on its own. Employees should exercise caution and critically evaluate unexpected signature or calendar requests, even when they appear to bear legitimate Microsoft branding and domains.

Email defense systems need to be capable of following redirects through trusted services and thoroughly evaluating the content that ultimately loads in the browser. Incident responders should meticulously preserve browser logs, identity event data, and email headers, as the malicious page may vanish once the browsing session concludes. These steps complement existing defenses against credential theft through session-cookie phishing, which aims to bypass multi-factor authentication. The campaign also highlights the critical difference between platform abuse and platform compromise. In this scenario, Teams and OAuth function as transit points, with attacker-controlled material introduced later and rendered locally. While blocking a known malicious domain may offer some temporary relief, detection strategies based on identifying unusual behavioral chains will prove far more resilient.

What You Should Do

  • Educate Users: Train employees to open document-signing or meeting requests only through established internal workflows, not from unexpected email messages.
  • Verify Unexpected Sign-ins: Instruct users that if a sign-in page appears after a calendar invite or redirect, they should close it immediately and independently verify the request through a known, secure channel.
  • Implement Phishing-Resistant MFA: Deploy strong authentication methods like FIDO2 security keys or passkeys to mitigate the impact of stolen credentials.
  • Enhance Email Gateway Configuration: Ensure email security solutions are configured to follow full redirect chains and analyze the content loaded at the final destination, not just the initial URL.
  • Monitor Browser Telemetry: Keep an eye on browser logs for suspicious activities such as unexpected service-worker registrations or unusual requests tied to externally sourced content.
  • Preserve Forensic Data: In case of a suspected incident, promptly collect and preserve browser logs, identity event data, and email headers, as the ephemeral nature of blob URLs means the malicious page may disappear.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Attack Steals Data via AI Workflows, No Jailbreak Needed
September 10, 2026
Critical LiteLLM Flaws Let Attackers Execute Code as Root, Steal Cloud Credentials
September 10, 2026
Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us