New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

https://www.securityweek.com/wp-content/uploads/2025/11/AI-phishing.jpeg

Future phishing campaigns may no longer involve a detectable physical web page.

Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.

The attack flow is similar to standard phishing since the victim must be steered to an external resource. In this campaign, however, the steering is obfuscated through trusted processes. It starts with a Docusign-themed email with an attached calendar invite. The calendar invite is irrelevant to the attack but makes the email appear to be a legitimate business communication.

A crafted redirect routes the user...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE