New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials

A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a sustained credential-phishing operation that fundamentally changes how phishing pages are delivered to […]

The post New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: