{"id":3891,"date":"2025-05-12T10:03:46","date_gmt":"2025-05-12T10:03:46","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/12\/new-phishing-attack-abusing-blob-urls-to-bypass-segs-and-evade-analysis\/"},"modified":"2025-05-12T10:03:46","modified_gmt":"2025-05-12T10:03:46","slug":"new-phishing-attack-abusing-blob-urls-to-bypass-segs-and-evade-analysis","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/12\/new-phishing-attack-abusing-blob-urls-to-bypass-segs-and-evade-analysis\/","title":{"rendered":"New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis"},"content":{"rendered":"<p>    New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity experts have identified a sophisticated phishing technique that exploits blob URIs (Uniform Resource Identifiers) to evade detection by Secure Email Gateways (SEGs) and <a href=\"https:\/\/cybersecuritynews.com\/postgresql-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">security analysis tools<\/a>.<\/p>\n<p>This emerging attack method leverages the unique properties of blob URIs, which are designed to display temporary data that can only be accessed by the browser that generated it.<\/p>\n<p>Unlike standard phishing sites that can be crawled and analyzed, blob URI-based attacks create credential harvesting pages that exist solely in the victim\u2019s browser memory, making them nearly invisible to traditional <a href=\"https:\/\/cybersecuritynews.com\/security-measures-that-help-protect-your-crypto\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a>.<\/p>\n<p>The attack begins with a seemingly innocuous email containing links to legitimate, allowlisted websites rather than directly to malicious domains.<\/p>\n<p>This initial misdirection helps the phishing attempt bypass email security filters that typically block messages with suspicious links.<\/p>\n<p>Upon reaching these intermediary pages, victims are then redirected through a series of steps that ultimately generate a local blob URI containing the actual phishing content.<\/p>\n<p>Cofense researchers <a href=\"https:\/\/cofense.com\/blog\/using-blob-urls-to-bypass-segs-and-evade-analysis\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this technique starting in mid-2022 and have observed its growing adoption among threat actors.<\/p>\n<p>According to their analysis, this method is particularly effective because the final credential phishing page exists only in the victim\u2019s browser, leaving no external URL for security tools to scan or block.<\/p>\n<p>This technical limitation creates a significant blind spot in conventional phishing detection systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgG7U0IKXzQFv8OdxtB4L-NGmN0L-iOwfgOqO3L28oLRoaYdfcEkbzDj4lyupGCwDEP8Ubh1U6imxjYiTwOJJK2lidCYuFvd3nesQuQ9S1CKMuoQCl50gk2Kx-gSclsGAnujyZwTjgAjhyphenhyphendqUq8yv4czrI4uzUYLKZqCQ2GAl7QeHSPKKEg6EuX7ZG0m-s\/s16000\/Infection%2520chain%2520%28Source%2520-%2520Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Infection chain (Source \u2013 Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>The infection chain follows a sophisticated multi-stage process. After the initial email bypasses the SEG, users are directed to legitimate services such as Microsoft <a href=\"https:\/\/cybersecuritynews.com\/hackers-onedrive-google-drive-malicious-traffic\/\" target=\"_blank\" rel=\"noreferrer noopener\">OneDrive<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEghJXyTm60eFhPycUYryJS7JM1yjnT9T0fXnbxaQI28lhAJSBFnfsjOXfF1U9ysgCcTPO0f0A62c6g1-P6z-mPJorfj6zWHEIaMaybPPbyiY1e3ARtlXVxzZZVvSYmRBwB7NXZAixppFkWfN_s7bvTTy7-MYn-Z4Yg_75I0mbwX09xdRuYNUjEECwqBbcI\/s16000\/Intermediary%2520site%2520before%2520redirecting%2520to%2520the%2520phishing%2520site%2520is%2520onedrive%255B.%255Dlive%255B.%255Dcom%2520%28Source%2520-%2520Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Intermediary site before redirecting to the phishing site is onedrive[.]live[.]com (Source \u2013 Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>What appears to be a standard <a href=\"https:\/\/cybersecuritynews.com\/qilin-operators-mimic-screenconnect-login-page\/\" target=\"_blank\" rel=\"noreferrer noopener\">login page<\/a> or document access screen is actually a carefully crafted redirection mechanism.<\/p>\n<p>When victims click to \u201cSign in\u201d or \u201cView document,\u201d they are seamlessly directed to a threat actor-controlled HTML page that generates a blob URI locally in the victim\u2019s browser.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWSH2NouuaIkx6VvRCMEC8wnQ9rdBAYlc9cBGq9-l5uPB5R6HD67zH999JwK1VU0NJQk0cHPKLh4G0lehGuETHK8ENwn4HguagBQif0L_GpS88pvkLCE-ZSVZv4DhrU-7XFTdl1vZiTvZkQ3o5R_L4ay_U5tVSfkGJjohUUeNhCrPOOjEUhnWU27WzKNk\/s16000\/A%2520blob%2520URI%2520page%2520spoofing%2520a%2520OneDrive%2520login%2520%28Source%2520-%2520Cofense%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">A blob URI page spoofing a OneDrive login (Source \u2013 Cofense)<\/figcaption><\/figure>\n<\/div>\n<p>The resulting phishing page, rendered from the blob URI (typically appearing as \u201cblob:https:\/\/domain.com\/random-string\u201d in the address bar), presents convincing login forms mimicking services like Microsoft 365 or OneDrive.<\/p>\n<p>Despite existing only in the local browser memory, these pages contain hidden functionality to exfiltrate captured credentials to remote servers controlled by the attackers.<\/p>\n<p>This technique represents a concerning evolution in phishing tactics, as it effectively circumvents both technological defenses and standard user awareness training that emphasizes checking URL validity before entering credentials.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong>Are you from the SOC and DFIR Teams? \u2013 Analyse Real time Malware Incidents with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/app.any.run\/?utm_source=csn_may&amp;utm_medium=article&amp;utm_campaign=mamona_analysis&amp;utm_term=090525&amp;utm_content=linktoregistration#register\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-abusing-blob-urls\/\">New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-abusing-blob-urls\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis Cybersecurity experts have identified a sophisticated phishing technique that exploits blob URIs (Uniform Resource Identifiers) to evade detection by Secure Email Gateways (SEGs) and security analysis tools. This emerging attack method leverages the unique properties of blob URIs, which are designed to display [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-3891","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3891"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3891"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3891\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}