New Phishing Attack Uses Microsoft Services to Hide Fake Pages

← Back to articles

New Phishing Attack Uses Microsoft Services to Hide Fake Pages

A new phishing technique is using trusted Microsoft services and blob URLs to generate malicious pages that exist only inside a victim’s browser, leaving no static website for security tools to block. Researchers confirmed the method after observing several campaigns that leveraged Microsoft’s own content delivery infrastructure to serve harmful content.

The attack begins with a phishing email that appears to come from a legitimate source, often a Microsoft‑related notification. The email contains a link that points to a Microsoft domain, which then delivers a blob URL—a special type of URL that references data stored in the browser’s memory rather than on a remote server. When the victim clicks the link, the browser loads a malicious page directly from the blob, making it appear as though the content originated from Microsoft. Because the page never resides on an external server, traditional web filters and blacklists cannot detect or block it.

Victims are typically targeted with credential‑stealing forms that mimic login pages for popular services such as Outlook or Azure. Since the page is rendered locally, any attempt to inspect the source code reveals only the blob reference, not the malicious HTML. This makes forensic analysis more difficult and gives attackers a stealthy channel to capture usernames, passwords, and sometimes two‑factor authentication codes.

The threat primarily affects users who receive phishing emails that appear to be from Microsoft or other trusted providers. Organizations that rely on standard URL filtering may find their defenses bypassed, as the malicious content does not travel over the network in a conventional way. The technique also complicates incident response, because there is no external host to quarantine or block.

To reduce the risk, users should verify any unsolicited Microsoft‑related email by checking the sender’s address and hovering over links before clicking. Enable multi‑factor authentication wherever possible, as it adds a layer of protection even if credentials are entered on a fake page. Keep browsers and operating systems up to date, because patches often address how blob URLs are handled. Use reputable anti‑phishing extensions that can flag suspicious links, and consider employing email security gateways that analyze message content for known phishing patterns.

ComputerScams.com offers free tools such as the PhishTank lookup and a browser extension that warns of potentially deceptive URLs. Running these tools can help spot a scam before it reaches the login screen.

A practical step you can take right now is to hover over every link in an email and compare the displayed URL with the known domain of the sender. If anything looks off, do not click and report the message to your email provider.

Source: Read the original report

Scroll to Top