Sunday, 27 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

Hackers found a sneaky new way to steal your login even when it’s encrypted – here’s how they’re pulling it off

Nexpressdaily
Last updated: May 26, 2025 12:09 pm
Nexpressdaily
Share
SHARE


  • Bypasses email gateways and security tools by never hitting a real server
  • Blob URIs mean phishing content isn’t hosted online, so filters never see it coming
  • No weird URLs, no dodgy domains, just silent theft from a fake Microsoft login page

Security researchers have uncovered a series of phishing campaigns that use a rarely exploited technique to steal login credentials, even when those credentials are protected by encryption.

New research from Cofense warns the method relies on blob URIs, a browser feature designed to display temporary local content, and cybercriminals are now abusing this feature to deliver phishing pages.

Blob URIs are created and accessed entirely within a user’s browser, meaning the phishing content never exists on a public-facing server. This makes it extremely difficult for even the most advanced endpoint protection systems to detect.


You may like

A hidden technique that slips past defenses

In these campaigns, the phishing process begins with an email that easily bypasses Secure Email Gateways (SEGs). These emails typically contain a link to what appears to be a legitimate page, often hosted on trusted domains such as Microsoft’s OneDrive.

However, this initial page doesn’t host the phishing content directly. Instead, it acts as an intermediary, silently loading a threat-actor-controlled HTML file that decodes into a blob URI.

The result is a fake login page rendered within the victim’s browser, designed to closely mimic Microsoft’s sign-in portal.

To the victim, nothing seems out of place – no strange URLs or obvious signs of fraud – just a prompt to log in to view a secure message or access a document. Once they click ‘Sign in,’ the page redirects to another attacker-controlled HTML file, which generates a local blob URI that displays the spoofed login page.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Because blob URIs operate entirely within the browser’s memory and are inaccessible from outside the session, traditional security tools are unable to scan or block the content.

“This method makes detection and analysis especially tricky,” said Jacob Malimban of the Cofense Intelligence Team.

“The phishing page is created and rendered locally using a blob URI. It’s not hosted online, so it can’t be scanned or blocked in the usual way.”

Credentials entered on the spoofed page are silently exfiltrated to a remote threat actor endpoint, leaving the victim unaware.

AI-based security filters also struggle to catch these attacks, as blob URIs are rarely used maliciously and may not be well-represented in training data. Researchers warn that unless detection methods evolve, this technique is likely to gain traction among attackers.

To defend against such threats, organizations are urged to adopt advanced Firewall-as-a-Service (FWAAS) and Zero Trust Network Access (ZTNA) solutions that can help secure access and flag suspicious login activity.

You might also like

Share This Article
Email Copy Link Print
Previous Article In the company of wolves … and Romans: hiking Portugal’s only national park | Walking holidays
Next Article Billy Joel diagnosed with rare brain disorder called Normal Pressure Hydrocephalus – what is it?

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

Halifax’s AI surveillance system inactive for new wildfire season – and the public wasn’t told

Halifax has been without an AI wildfire surveillance system since October when the pilot project…

By Nexpressdaily

Assisted dying bill will put pressure on vulnerable to end lives early, campaigners warn

Sign up for the View from Westminster email for expert analysis straight to your inboxGet…

By Nexpressdaily

Before naming 2028 nominee, Democrats have to decide which state will weigh in first

DES MOINES, Iowa -- Before they can name their next presidential nominee, Democrats will have…

By Nexpressdaily

You Might Also Like

Technology

Final Fantasy fans, now is the time to get into Magic: The Gathering

By Nexpressdaily
Technology

Anthropic brings web search to free Claude users

By Nexpressdaily
Technology

Volvo is introducing the first multi-adaptive seatbelt technology on the EX60 EV

By Nexpressdaily
Technology

Hollywood’s pivot to AI video has a prompting problem

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?