logo

New Voicemail-Themed Phishing Attacks

ID: f28d096b-c07f-5f8d-b7a1-a1155212c911

STIX ID: report--f28d096b-c07f-5f8d-b7a1-a1155212c911

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes an active July 2020 voicemail-themed credential-phishing campaign targeting large enterprises: attackers send HTML email attachments (often named with telephone icons) containing JavaScript that redirects to credential-phishing landing pages spoofing Office 365, OWA, Gmail, Mimecast and others. The campaign uses evasion techniques including encoded JavaScript, externally hosted long-named JS payloads, meta-refresh redirects, and Google reCAPTCHA to thwart automated analysis; credentials are exfiltrated (Base64-encoded) to attacker servers, and the report includes a comprehensive list of .xyz/.club/.online domains and external JS IOCs observed in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.