A phishing campaign delivers DocuSign-themed emails with calendar-invite attachments and routes recipients through legitimate Microsoft OAuth and Microsoft Teams infrastructure before loading a credential-harvesting page from cdn.bloom[.]io. Rather than hosting a conventional phishing site, the campaign causes the victim’s browser to assemble the fake login interface as a blob: URL, leaving fewer static URLs and page artifacts for scanners to detect.
The operation appears to use a centrally managed phishing platform: the in-browser page registers a service worker, runs within a sandboxed iframe, and receives backend configuration and live instructions through browser messaging. Defenders should inspect complete email click paths and OAuth redirect chains, monitor blob-URL activity and anomalous service-worker registrations, and prioritize browser telemetry, behavioral controls, and phishing-resistant MFA.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Barracuda analyzed a phishing campaign that uses DocuSign-themed calendar invites, Microsoft OAuth and Teams redirects, and cdn.bloom[.]io to render credential-harvesting pages as blob URLs within victims’ browsers. The operation uses service workers, sandboxed iframes, and hidden command-and-control configuration, indicating a centrally managed phishing platform capable of dynamically directing victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceitpro.com
Open sourcehelpnetsecurity.com
Open sourcecyberveille.ch
Open sourcesecurityweek.com
Open sourceblog.barracuda.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.