Fake Voicemail SVGs Bypass Email Defenses

Infosecurity Magazine · Medium sophistication
Last updated August 28, 2026

A large phishing campaign sent tens of thousands of emails with SVG attachments disguised as voicemail notifications. The SVG files hid obfuscated JavaScript that, when opened, rebuilt code and contacted a remote endpoint. Many messages also impersonated “internal” senders and slipped past native spam filtering.

Key findings

  • Two-month campaign (June 1–August 4, 2026) delivered 26,589 phishing emails across 5,527 organizations.
  • Lure was an “internal voicemail notification,” with subjects personalized using the recipient’s email local-part.
  • SVG attachments contained obfuscated JavaScript and fetched a remote endpoint after runtime reconstruction/deferred execution.
  • Attachments were labeled with a misleading MIME type (text/plain) to evade scanners that trust declared content type.
  • 95% of messages “claimed to come from the recipient's own domain” (internal impersonation), while actually coming from an external sender.
  • Microsoft native spam scoring rated most of the messages as not spam (SCL 0–1 for 75% of messages).

Who’s being targeted

  • Commonly targeted roles: All employees, IT / Email administrators, Security awareness team, Helpdesk / Service desk.
  • Affected industries: Cross-industry (multiple organizations targeted).
  • Attack channels: email, website.
  • Impersonated: Internal sender from the recipient’s own domain (spoofed), Internal voicemail system notification.

Awareness takeaways

  • Treat unexpected voicemail emails with attachments as suspicious, especially if you weren’t expecting a voicemail.
  • Be cautious of messages that look internal (your own domain) but may be spoofed, verify the sender through trusted channels if unsure.
  • Don’t assume an attachment is safe because it looks like an image or is labeled as plain text, attackers can hide scripts in SVG files.
  • Native spam filters can miss large campaigns; employees should still follow reporting procedures even when messages aren’t marked as spam.

Red flags to watch for

  • Unexpected voicemail attachment delivered by email
  • Sender appears internal but actually comes from an external, unauthenticated source
  • Attachment is an SVG/XML file masquerading as a voicemail
  • File type mismatch (voicemail-themed name but SVG/XML content)
  • Attachment is treated as harmless text due to MIME mislabeling
  • Hidden script behavior (deferred execution / runtime injection)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email that looks internal: subject says “New voicemail for j.smith” and it’s from your own domain. Feels legit, right? But this two‑month campaign blasted 26,000+ of these. The “voicemail” attachment is actually an SVG file with hidden JavaScript that rebuilds code and calls a remote site, while Microsoft spam scoring says SCL 0 or 1, not spam. Here’s the trick: 95% pretended to be from your own domain, but really came from unknown external senders. The file says voicemail, but the type is SVG or XML, mislabeled as text/plain so scanners think it’s harmless. If you weren’t expecting a voicemail, don’t open the attachment. Report the email in Outlook instead and let security check if that “voicemail SVG” is really a trap.

Similar attacks

Phish Page Built Inside Your Browser

Phish Page Built Inside Your Browser

Researchers reported a real phishing campaign that uses legitimate Microsoft OAuth and Teams pages to make the journey look trustworthy. Instead of hosting a fake login site on a suspicious domain, the attackers render the phishing page inside the victim’s own browser using a temporary “blob URL,”…

September 10, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Spark RAT Phish Hits Cambodia With “Official” Lures

Spark RAT Phish Hits Cambodia With “Official” Lures

A real campaign targeting people and organizations in Cambodia uses phishing emails with localized “official-looking” themes to trick recipients into running an installer from a compressed file. Once executed, the malware chain deploys Spark RAT for remote control and uses a vulnerable OPSWAT…

August 27, 2026