Voicemail Trap: German-Language Voicemail Lure Leads to Remote Access
ID: e77edf00-625c-5173-a243-cbefe7c576fb
STIX ID: report--e77edf00-625c-5173-a243-cbefe7c576fb
Feed Name: Censys Blog
Threat Score
Censys observed a voicemail-themed social engineering campaign (≈86 cadillac.ps web properties) that tricks German-language targets into downloading and running a BAT which plays decoy audio and silently installs the legitimate Remotely RMM agent, enrolling systems into an attacker-controlled Remotely server; the report includes domains, S3 audio URL, script and binary hashes, Remotely download URLs, and on-host artifacts for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
