Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

August 28, 2026

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

August 28, 2026

Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Gia

August 28, 2026
Facebook X (Twitter) Instagram
Friday, August 28
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
News

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Team-CWDBy Team-CWDAugust 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A two-month phishing campaign used scalable vector graphics (SVG) attachments disguised as voicemail files to smuggle obfuscated JavaScript past email defenses, with 26,589 messages detected across 5527 organizations.

Email security vendor INKY, which is part of Kaseya, detected and flagged the messages. In a technical write-up published on August 27, INKY said that the campaign ran from June 1 through August 4, 2026 in waves, largely stopping at weekends.

The largest spike came on June 3, when 2432 messages reached 1149 organizations. INKY said the campaign was still running when its analysis closed.

The operation showed little evidence of precision targeting. The median organization received two messages, while 32% received only one.

The 10 most-affected organizations accounted for just 6% of the total volume, consistent with broad spray delivery rather than a tightly focused spear-phishing campaign.

SVG Smuggling Adds a Second Evasion Layer

The lure presented itself as an internal voicemail notification, with 99.5% of subjects incorporating the local part of the recipient’s own email address. Attachments used voicemail-style names and carried SVG and XML content.

Those attachments declared a MIME type of text/plain rather than image/svg+xml, so a scanner keying on the stated type would see an innocuous text file rather than active content.

That distinction mattered because SVG files can contain JavaScript. In the samples analyzed by INKY, a minimal graphic shell concealed obfuscated script that reconstructed strings at runtime and fetched a remote endpoint.

The code also used deferred execution and runtime script injection, making its behavior harder to identify through static inspection.

Read more on SVG phishing: AI-Generated Code Used in Phishing Campaign Blocked by Microsoft

Native Spam Filtering Missed Most Messages

The campaign leaned heavily on internal spoofing. INKY said 95% of the messages claimed to come from the recipient’s own domain while arriving from an external sender that had never authenticated to the organization’s mail server.

Native spam scoring treated most of the campaign as harmless. Some 19,994 messages (75%), received a Microsoft Spam Confidence Level (SCL) of 0 or 1, which Microsoft treats as not spam, while only 4777 (18%) were assigned SCL 5.

INKY noted that the campaign was built from a single template, yet the same message drew different native verdicts depending on the receiving mailbox.

These findings reinforce how the campaign combined several individually plausible signals: a familiar voicemail pretext, an image format, recipient-specific personalization and an internal sender impersonation.

The SVG attachment supplied the bridge between those social-engineering elements and executable browser content.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Team-CWD
  • Website

Related Posts

News

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

August 28, 2026
News

Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Gia

August 28, 2026
News

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

August 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why children’s data is a long-term identity risk

June 3, 2026

Look out for phony verification pages spreading malware

September 14, 2025

Is it time for internet services to adopt identity verification?

January 14, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.