Teams Redirects Hide Phishing Pages in Browser Sessions
Barracuda analyzed a phishing campaign that starts with a DocuSign-themed email and an attached calendar invite, then uses a Microsoft Teams redirect to deliver a page that the victim’s browser turns into a blob URL. The result is a phishing page that exists only inside the browser session, not as a stable website defenders can blacklist.
Because the page is assembled after the click inside trusted Microsoft services, there is no normal live URL for email gateways or web filters to hold onto. The flow can also lean on browser features such as service workers and iframes to steer the session, which makes the lure look more like ordinary app traffic than a public phishing site.
For teams that rely on URL-based blocking, the exposure shifts from scanning domains to watching the click path and browser behavior. If Microsoft 365 and Teams sit in the middle of your users’ workflow, the phish may never produce the kind of static indicator your defenses were built to catch.