
Phishers Abuse DocuSign, Rewards, and “Verification”
This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…
A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page to appear legitimate. Victims were redirected through multiple trusted services and instructed to approve a Microsoft device-code login session, giving attackers access without stealing a password via a fake login page.
The campaign, tracked as Kali365 Ringer, began with a voicemail-style notification telling the recipient they had a missed call and needed to review a message. This simple pretext gave the attacker a reason to push the user toward a link. Clicking through led to a page built on Google Sites, a legitimate hosting platform that gave the phishing content a familiar, trustworthy appearance rather than an obvious spoofed domain.
From there, the victim was redirected through a chain of well-known services, including a Google redirector and an OCI API Gateway, before landing on a Cloudflare-protected host controlled by the attacker. Rather than presenting a fake login form to harvest a password, the page instructed the user to authorize a Microsoft device-code session. Approving that prompt handed the attacker an active, authenticated session without ever touching the victim's password.
Several design choices made this lure effective:
Defenders and employees should be alert to a few consistent signals from this campaign:
The same landing page, sender subdomain, subject pattern, and fake internal reference ID were reused across multiple financial and insurance organizations targeted on the same day, a pattern that security teams can use to detect and block related campaign infrastructure quickly.
Organizations, particularly in finance and insurance where this campaign concentrated, should reinforce a simple rule: never approve a Microsoft device-code or device login prompt that was not self-initiated. Employees should also be encouraged to verify unexpected voicemail or missed-call messages through known internal channels before clicking any embedded link. Because this technique bypasses traditional password-harvesting defenses, awareness training should specifically cover device-code approval flows, not just fake login pages, and staff should have a clear, fast path to report suspicious authorization requests to IT or helpdesk teams.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Kali365 Ringer is a device-code phishing campaign identified by ZeroBEC that used a fake missed-call voicemail notification to lure users toward approving an attacker-controlled Microsoft login session.
Instead of stealing a password on a fake login page, the attacker has the victim approve a real Microsoft device-code session, giving access without ever needing to steal or guess credentials.
The campaign used a trusted Google Sites wrapper and routed victims through multiple reputable platforms, including a Google redirector, an OCI API Gateway, and a Cloudflare-protected host, before reaching the final destination.
The campaign targeted an unnamed regulated financial customer and reused the same landing page, subject pattern, and fake internal reference ID against multiple financial and insurance organizations on the same day.
You get an email: “Missed call – new voicemail.” Looks internal, says click to listen. That’s the whole trap. You click, and it opens a legit-looking Google Sites page, then bounces through a couple trusted links before landing on a Microsoft device-code prompt asking you to approve access. Here’s the twist: this “Kali365 Ringer” scam never steals your password. If you approve that Microsoft device code for a voicemail you didn’t start, you hand them live access to your account. If a voicemail or missed-call email ever leads to a Microsoft device-code prompt you didn’t initiate, stop and report it to security immediately, don’t approve anything.

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…