logo

Voicemail Trap: German-Language Voicemail Lure Leads to Remote Access

ID: e77edf00-625c-5173-a243-cbefe7c576fb

STIX ID: report--e77edf00-625c-5173-a243-cbefe7c576fb

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-27

Author: Ivonne Francia

...
...

Censys observed a voicemail-themed social engineering campaign (≈86 cadillac.ps web properties) that tricks German-language targets into downloading and running a BAT which plays decoy audio and silently installs the legitimate Remotely RMM agent, enrolling systems into an attacker-controlled Remotely server; the report includes domains, S3 audio URL, script and binary hashes, Remotely download URLs, and on-host artifacts for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.