The hackers found a new cunning way to steal their login even when it is encrypted, this is how they are achieving




  • Avoid email link doors and safety tools when never hitting a real server
  • Blob Uris means that phishing content is not lodged online, so filters never see it coming
  • There are no strange URLs, without doubtful domains, only silent robbery of a false Microsoft login page

Security researchers have discovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

A new research by Cofense warns that the method is based on Blob URI, a feature of the browser designed to show temporary local content, and cybercriminals are now abusing this feature to deliver Phishing pages.

Leave a Comment

Your email address will not be published. Required fields are marked *