An ongoing credential-phishing campaign has used automated voicemail transcript notifications to target more than 7,800 organizations, according to Check Point Research (CPR), as reported by TechRadar.
Between August 17 and August 31, CPR identified more than 58,000 emails tied to the campaign. Researchers said attackers used more than 38,400 spoofed sender addresses across more than 9,300 spoofed domains.
The messages use subject lines beginning with “Automated transcript”, followed by a partially redacted phone number and a random tracking string. Each email includes an attachment designed to resemble a call recording, but the file is an SVG image rather than an audio file.
Because SVG is an XML-based document that can contain JavaScript, opening it in a browser can redirect a recipient to a spoofed login page. The recipient’s email address is hardcoded into the URL, allowing the fake form to pre-fill the username.
CPR said the campaign appears aimed at stealing credentials for email accounts and business services. The researchers described it as an example of attackers adapting to increasingly automated workplace workflows.
Comments
0No comments yet. Be the first to comment.