Fake Voicemail SVGs Bypass Email Defenses

Infosecurity Magazine · Medium sophistication
Last updated August 28, 2026

A large phishing campaign sent tens of thousands of emails with SVG attachments disguised as voicemail notifications. The SVG files hid obfuscated JavaScript that, when opened, rebuilt code and contacted a remote endpoint. Many messages also impersonated “internal” senders and slipped past native spam filtering.

Key findings

  • Two-month campaign (June 1–August 4, 2026) delivered 26,589 phishing emails across 5,527 organizations.
  • Lure was an “internal voicemail notification,” with subjects personalized using the recipient’s email local-part.
  • SVG attachments contained obfuscated JavaScript and fetched a remote endpoint after runtime reconstruction/deferred execution.
  • Attachments were labeled with a misleading MIME type (text/plain) to evade scanners that trust declared content type.
  • 95% of messages “claimed to come from the recipient's own domain” (internal impersonation), while actually coming from an external sender.
  • Microsoft native spam scoring rated most of the messages as not spam (SCL 0–1 for 75% of messages).

Who’s being targeted

  • Commonly targeted roles: All employees, IT / Email administrators, Security awareness team, Helpdesk / Service desk.
  • Affected industries: Cross-industry (multiple organizations targeted).
  • Attack channels: email, website.
  • Impersonated: Internal sender from the recipient’s own domain (spoofed), Internal voicemail system notification.

Awareness takeaways

  • Treat unexpected voicemail emails with attachments as suspicious, especially if you weren’t expecting a voicemail.
  • Be cautious of messages that look internal (your own domain) but may be spoofed, verify the sender through trusted channels if unsure.
  • Don’t assume an attachment is safe because it looks like an image or is labeled as plain text, attackers can hide scripts in SVG files.
  • Native spam filters can miss large campaigns; employees should still follow reporting procedures even when messages aren’t marked as spam.

Red flags to watch for

  • Unexpected voicemail attachment delivered by email
  • Sender appears internal but actually comes from an external, unauthenticated source
  • Attachment is an SVG/XML file masquerading as a voicemail
  • File type mismatch (voicemail-themed name but SVG/XML content)
  • Attachment is treated as harmless text due to MIME mislabeling
  • Hidden script behavior (deferred execution / runtime injection)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email that looks internal: subject says “New voicemail for j.smith” and it’s from your own domain. Feels legit, right? But this two‑month campaign blasted 26,000+ of these. The “voicemail” attachment is actually an SVG file with hidden JavaScript that rebuilds code and calls a remote site, while Microsoft spam scoring says SCL 0 or 1, not spam. Here’s the trick: 95% pretended to be from your own domain, but really came from unknown external senders. The file says voicemail, but the type is SVG or XML, mislabeled as text/plain so scanners think it’s harmless. If you weren’t expecting a voicemail, don’t open the attachment. Report the email in Outlook instead and let security check if that “voicemail SVG” is really a trap.

Similar attacks

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Spark RAT Phish Hits Cambodia With “Official” Lures

Spark RAT Phish Hits Cambodia With “Official” Lures

A real campaign targeting people and organizations in Cambodia uses phishing emails with localized “official-looking” themes to trick recipients into running an installer from a compressed file. Once executed, the malware chain deploys Spark RAT for remote control and uses a vulnerable OPSWAT…

August 27, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026