Hackers found a lusky new way to steal your login even when encrypted – here’s how they pull it off


  • Bypassing E -Mail -Gateways and security tools by never hitting a real server
  • Blob uris means phishing — content is not host online so filters never see it coming
  • No weird URLs, No Dodgy Domains, Just Silent Theft from a False Microsoft -Login -side

Security researchers have revealed a number of phishing campaigns that use a rarely utilized technique to steal login -credentials, even when these credentials are protected by encryption.

New research from Cofense warns that the method is dependent on blob uris, a browser function designed to display temporary local content, and cyber criminals are now abusing this feature of providing phishing sites.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top