{"id":12470,"date":"2026-04-29T10:01:25","date_gmt":"2026-04-29T10:01:25","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/new-blobphish-attack-leverages-browser-blob-objects-to-steal-users-login-credentials\/"},"modified":"2026-04-29T10:01:25","modified_gmt":"2026-04-29T10:01:25","slug":"new-blobphish-attack-leverages-browser-blob-objects-to-steal-users-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/new-blobphish-attack-leverages-browser-blob-objects-to-steal-users-login-credentials\/","title":{"rendered":"New BlobPhish Attack Leverages Browser Blob Objects to Steal Users\u2019 Login Credentials"},"content":{"rendered":"<p>    New BlobPhish Attack Leverages Browser Blob Objects to Steal Users\u2019 Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools.<\/p>\n<p>BlobPhish is a sustained credential-phishing operation that fundamentally changes how phishing pages are delivered to victims.<\/p>\n<p>Rather than hosting <a href=\"https:\/\/cybersecuritynews.com\/flowerstorm-phishing-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake login pages<\/a> on attacker-controlled servers and serving them over standard HTTP, BlobPhish generates phishing pages\u00a0<em>entirely inside the victim\u2019s browser<\/em>\u00a0using JavaScript Blob objects.<\/p>\n<p>The result is a phishing payload that exists only in memory, leaving no file on disk, no cache artifact, and no suspicious HTTP request in proxy logs for security tools to flag.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 85%,rgb(169,184,195) 100%)\"><strong><a href=\"https:\/\/any.run\/plans-ti\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=blobphish&amp;utm_content=plans+ti+sales&amp;utm_term=280426#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><u>Close the gap before it becomes business risk<\/u><\/a>.<\/strong> Give your SOC full visibility into suspicious activity.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjFle5jzl5JuTw-xkcVAqa2WxGIVjRPnPKnx-blcyU63jQW3qFYnx504amxHsclbGQPxbkdGVyPgnuBqhbGJiLM5qTGmjJ37suAsWmPnbnzc_b4yeyAgj6mU39-yNHkWyTTNjXg5B7SNnYbiMK2WtiNIzhOhHjDw4lqxGw_-RShpKkD_zrnBXtS-fYU5mU\/s16000\/blob_2-1536x723%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Blobphish attack detonated in the sandbox<\/em>\u00a0<\/figcaption><\/figure>\n<p>First observed in October 2024, the campaign has run uninterrupted for over 18 months and recorded a significant spike in activity in February 2026, confirming it as a mature, well-maintained threat operation rather than a short-lived opportunistic attack.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><a href=\"https:\/\/any.run\/plans-ti\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=blobphish&amp;utm_content=plans+ti+sales&amp;utm_term=280426#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><u><strong>Accelerate investigations and stop incidents earlier<\/strong><\/u><\/a>. Leverage threat intelligence to improve threat visibility.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-blobphish-kill-chain\"><strong>BlobPhish kill chain<\/strong><\/h2>\n<p>The BlobPhish kill chain is elegantly designed to defeat both network-based and file-based defenses:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Initial Access:<\/strong>\u00a0The victim receives a phishing email \u2014 often mimicking a financial alert, invoice, or document share \u2014 containing a link to a trusted-looking service such as DocSend or a shortened URL via t.co. PDF attachments carrying QR codes that lead to malicious JavaScript pages have also been observed, particularly in energy-sector campaigns.<\/li>\n<li>\n<strong>Loader Execution:<\/strong>\u00a0Clicking the link redirects the victim to an attacker-controlled HTML page hosting a JavaScript loader. Using jQuery, the loader invisibly creates a hidden\u00a0<code>&lt;a&gt;<\/code>\u00a0anchor element, Base64-decodes a bundled <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-abuse-proofpoints-link-wrapping-features\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing payload<\/a> using\u00a0<code>atob()<\/code>, constructs a\u00a0<code>Blob<\/code>\u00a0object of type\u00a0<code>text\/html<\/code>, generates a\u00a0<code>blob:https:\/\/<\/code>\u00a0URL via\u00a0<code>window.URL.createObjectURL()<\/code>, and forces the browser to navigate to it \u2014 all without any visible user interaction.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiPjd4hzDl8gi20V2y7MBLu8btmSEVhpxSMPCy2rFfQQkBEw0tevR0nx262YWW5XMJeBkOBZrC8tE17yYvgJmKhWXGdXHGCEOO3wJ6cZEVLM-gHLcSphPkH_bsZ6qRIW6pitfCFTzs8yuuijK406pYYHFToepr23MNdbSGZHylRTrnp4kAOEa-P8EPklw0\/s16000\/blob_3%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Code responsible for blob object download<\/em>\u00a0<\/figcaption><\/figure>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Evidence Destruction:<\/strong>\u00a0Immediately after navigation, the loader calls\u00a0<code>window.URL.revokeObjectURL()<\/code>\u00a0and removes the anchor element from the DOM, destroying any remaining in-memory trace of the loader\u2019s operation.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJ0QbEXdKSi0swlMc_0qOh7ynvLDgWrDa7e1gtTUB_CTGbLaClXPjdgn3iBF9eWfOTvvNgA_B-5KdizQwmyMbP5PLbIYweHEyVHcA4hfq9hqoDNE0aZbH1UsnADQcdnPdBlc6nmfcgBqzaSgG-krGU9v6OzMWgYjUZ-0RZiat7SS1kVMSojvNQ2AQXz3c\/s16000\/blob_5-1%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Code responsible for blob object download<\/em><\/figcaption><\/figure>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Credential Harvest:<\/strong>\u00a0The victim is presented with a convincing replica of a Microsoft 365, Chase, Capital One, or other financial service login page. The browser address bar shows a\u00a0<code>blob:https:\/\/<\/code>\u00a0URL, which can appear legitimate to an untrained eye. A failed-login counter forces victims to re-enter credentials multiple times, maximizing harvest accuracy. Captured data is exfiltrated via HTTP POST to attacker-controlled endpoints matching the pattern\u00a0<code>*\/res.php<\/code>,\u00a0<code>*\/tele.php<\/code>, or\u00a0<code>*\/panel.php<\/code>\u00a0\u2014 hosted predominantly on compromised legitimate WordPress sites.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi5jrnqXOiF4HmfH8Ip4FstixOxfQMfXERHkTkefEqrY78Yqy3UT4Ezgq7CjdsTB0jV4WAY6xn7OkfJAGHAutwykzh8NNmc_d5iLGCZut7EpLMgf-I2dp2ykv4ruoLgtkRV1_5hm7gCuP16kkr1sfiYpG_p6sVR1N4eZiidtGmFhfHLZCkKwk7X27GA1VE\/s16000\/blob_10%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Data exfiltration patterns<\/em><\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"targeted-services-and-global-reach\"><strong>BlobPhish Evades Conventional Defenses<\/strong><\/h2>\n<p>BlobPhish impersonates a broad list of high-value platforms, including\u00a0Microsoft 365, OneDrive, SharePoint, Chase, Capital One, FDIC, E*TRADE, Charles Schwab, Morgan Stanley\/Merrill Lynch, American Express, PayPal, and Intuit.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi0y3R8Z0Gk2O40Bz_iDGCZ8tRpDwrDdgGZQfvOuLSbIqs3-Bxqgzj0WYO5_iXC1s3Akh6d-d6-yLm4qdJQQ5vPkI-XQWspgFE6tjyD11FzR8wpIwx9Yd_u7f6Dq8srcdRFQxQlSsOjE_Jk9kWnHV0wl8GA9hK0eHfy0hFU8g02xi7yzrod1q3DOvWY5Fc\/s16000\/blob_13%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\"><em>Phishing form imitating Chase Banking login page<\/em><\/figcaption><\/figure>\n<p>Although financial and cloud-productivity lures dominate, victim organizations span Finance, Manufacturing, Education, Government, Transport, and Telecommunications sectors.<\/p>\n<p>Geographically, approximately\u00a0one-third of observed victims are U.S.-based, with additional activity recorded across Germany, Poland, Spain, Switzerland, the UK, Australia, South Korea, Saudi Arabia, Qatar, Jordan, India, and Pakistan.<\/p>\n<p>The\u00a0<code>blob:https:\/\/<\/code>\u00a0scheme is the campaign\u2019s core evasion innovation. Because the phishing page is never transmitted over the network as a standalone HTTP response:<\/p>\n<ul class=\"wp-block-list\">\n<li>URL reputation engines\u00a0cannot block it \u2014 no external URL to scan.<\/li>\n<li>Proxy logs\u00a0show no suspicious requests for the phishing page itself.<\/li>\n<li>Secure Email Gateways (SEGs)\u00a0miss the payload, which materializes only after delivery.<\/li>\n<li>File-based endpoint solutions\u00a0find nothing \u2014 no file is ever written to disk.<\/li>\n<li>Cache forensics\u00a0return empty \u2014 the Blob URL is revoked before investigators can inspect it.<\/li>\n<\/ul>\n<p>A single successful BlobPhish compromise can cascade into\u00a0Business Email Compromise (BEC) fraud, full Microsoft 365 tenant takeover, unauthorized wire transfers, investment account manipulation, and ransomware deployment following lateral movement.<\/p>\n<p>Regulatory consequences, including GDPR 72-hour breach notification, SEC cybersecurity incident disclosure, and FFIEC authentication guidance, add material legal exposure on top of operational damage.<\/p>\n<h2 class=\"wp-block-heading\" id=\"key-indicators-of-compromise-iocs\"><strong>Key Indicators of Compromise (IOCs)<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">IOC Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Example<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Loader URL<\/td>\n<td><code>hxxps[:\/\/]mtl-logistics[.]com\/blb\/blob[.]html<\/code><\/td>\n<\/tr>\n<tr>\n<td>Exfiltration endpoint<\/td>\n<td><code>hxxps[:\/\/]mtl-logistics[.]com\/css\/sharethepoint\/point\/res[.]php<\/code><\/td>\n<\/tr>\n<tr>\n<td>Capital One exfil<\/td>\n<td><code>hxxps[:\/\/]wajah4dslot[.]com\/wp-includes\/certificates\/tmp\/\/res[.]php<\/code><\/td>\n<\/tr>\n<tr>\n<td>Chase Banking exfil<\/td>\n<td><code>hxxps[:\/\/]hnint[.]net\/cgi-bin\/peacemind\/\/res[.]php<\/code><\/td>\n<\/tr>\n<tr>\n<td>E*TRADE exfil<\/td>\n<td><code>hxxps[:\/\/]ftpbd[.]net\/wp-content\/plugins\/cgi-\/trade\/trade\/\/res[.]php<\/code><\/td>\n<\/tr>\n<tr>\n<td>tele.php variant<\/td>\n<td><code>hxxps[:\/\/]_wildcard_[.]gonzalezlawnandlandscaping[.]com\/\u2026\/tele[.]php<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Additional compromised domains include\u00a0<code>larva888[.]com<\/code>,\u00a0<code>riobeautybrazil[.]com<\/code>,\u00a0<code>i-seotools[.]com<\/code>, and\u00a0<code>mts-egy[.]net<\/code>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"defensive-recommendations\"><strong>Defensive Recommendations<\/strong><\/h2>\n<p>Security teams should take the following priority actions:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Deploy sandbox analysis<\/strong>\u00a0capable of executing JavaScript in real browsers to detonate blob-based payloads safely before they reach end users<\/li>\n<li>\n<strong>Hunt proactively<\/strong>\u00a0using the\u00a0<code>BlobPhishLoaderHTML<\/code>\u00a0YARA rule and URL pivot queries (<code>url:\"\/res.php$\"<\/code>,\u00a0<code>url:\"*\/blob.html$\"<\/code>) in threat intelligence platforms<\/li>\n<li>\n<strong>Enforce phishing-resistant MFA<\/strong>\u00a0(FIDO2\/hardware keys) on all Microsoft 365 and banking portals to limit post-compromise blast radius<\/li>\n<li>\n<strong>Integrate live TI feeds<\/strong>\u00a0that push BlobPhish IOCs into firewalls, proxies, and SIEM rules automatically as attacker infrastructure rotates<\/li>\n<li>\n<strong>Train employees<\/strong>\u00a0to recognize unexpected\u00a0<code>blob:https:\/\/<\/code>\u00a0URLs in browser address bars as a red flag<\/li>\n<\/ul>\n<p>BlobPhish demonstrates that the phishing threat has outpaced perimeter and static-signature defenses.<\/p>\n<p>Effective protection now demands dynamic behavioral analysis, continuous threat hunting, and automated intelligence propagation operating at the speed of attacker infrastructure rotation.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 84%,rgb(169,184,195) 100%)\"><a href=\"https:\/\/any.run\/plans-ti\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=blobphish&amp;utm_content=plans+ti+sales&amp;utm_term=280426#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><u><strong>Prevent high-stakes credential attacks with enterprise-grade<\/strong><\/u><\/a>\u00a0intelligence. Reduce risk, not just response time.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/blobphish-phishing-attack\/\">New BlobPhish Attack Leverages Browser Blob Objects to Steal Users\u2019 Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/blobphish-phishing-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New BlobPhish Attack Leverages Browser Blob Objects to Steal Users\u2019 Login Credentials A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1405,129,63],"tags":[130],"class_list":["post-12470","post","type-post","status-publish","format-standard","hentry","category-any-run","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12470"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12470"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12470\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}