Voicemail Lure Drives Microsoft Device-Code Phish

The Hacker News · Medium sophistication
Last updated July 30, 2026

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page to appear legitimate. Victims were redirected through multiple trusted services and instructed to approve a Microsoft device-code login session, giving attackers access without stealing a password via a fake login page.

How the attack worked

The campaign, tracked as Kali365 Ringer, began with a voicemail-style notification telling the recipient they had a missed call and needed to review a message. This simple pretext gave the attacker a reason to push the user toward a link. Clicking through led to a page built on Google Sites, a legitimate hosting platform that gave the phishing content a familiar, trustworthy appearance rather than an obvious spoofed domain.

From there, the victim was redirected through a chain of well-known services, including a Google redirector and an OCI API Gateway, before landing on a Cloudflare-protected host controlled by the attacker. Rather than presenting a fake login form to harvest a password, the page instructed the user to authorize a Microsoft device-code session. Approving that prompt handed the attacker an active, authenticated session without ever touching the victim's password.

Why it succeeded

Several design choices made this lure effective:

  • A voicemail or missed-call theme creates a sense of missing something important, prompting quick action.
  • Using Google Sites as a wrapper avoids the visual red flags of an unfamiliar or misspelled domain.
  • Routing traffic through multiple reputable platforms before reaching attacker infrastructure adds legitimacy and can complicate detection.
  • Asking for device-code approval instead of a password sidesteps user training focused on spotting fake login pages.

What to watch for

Defenders and employees should be alert to a few consistent signals from this campaign:

  • Unexpected voicemail or missed-call notifications that push a login or approval action.
  • Login or authorization flows hosted on general-purpose site builders like Google Sites rather than a known corporate domain.
  • Multiple redirects through unrelated third-party services before reaching a final page.
  • Any Microsoft device-code prompt that appears without the user having initiated a sign-in themselves.

The same landing page, sender subdomain, subject pattern, and fake internal reference ID were reused across multiple financial and insurance organizations targeted on the same day, a pattern that security teams can use to detect and block related campaign infrastructure quickly.

Building resistance

Organizations, particularly in finance and insurance where this campaign concentrated, should reinforce a simple rule: never approve a Microsoft device-code or device login prompt that was not self-initiated. Employees should also be encouraged to verify unexpected voicemail or missed-call messages through known internal channels before clicking any embedded link. Because this technique bypasses traditional password-harvesting defenses, awareness training should specifically cover device-code approval flows, not just fake login pages, and staff should have a clear, fast path to report suspicious authorization requests to IT or helpdesk teams.

Key findings

  • ZeroBEC reported a real device-code phishing attack (“Kali365 Ringer”) targeting an unnamed regulated financial customer.
  • The lure used a “missed-call notification” and a “trusted Google Sites wrapper” before redirecting through multiple reputable platforms to the attacker infrastructure.
  • Users were instructed to approve an attacker-controlled Microsoft device-code session instead of entering credentials on a fake login page.
  • The same Google Sites landing page and subject pattern were reused to target multiple organizations on the same day.

Who’s being targeted

  • Commonly targeted roles: All employees (Microsoft 365 users), Finance and Accounting, Insurance operations, Helpdesk / IT support (triage of login-approval reports).
  • Affected industries: Financial services, Insurance, Regulated financial organizations.
  • Attack channels: email, website.
  • Impersonated: Internal voicemail/telephony service (voicemail notification) using Google Sites as a trusted wrapper.

Red flags to watch for

  • Voicemail/missed-call message pushes you to sign in or approve access unexpectedly
  • Legitimate-looking Google Sites page used as a wrapper for login/authorization flow
  • Multiple redirects through well-known services before reaching the final destination
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Kali365 Ringer attack?

Kali365 Ringer is a device-code phishing campaign identified by ZeroBEC that used a fake missed-call voicemail notification to lure users toward approving an attacker-controlled Microsoft login session.

Why is device-code phishing dangerous?

Instead of stealing a password on a fake login page, the attacker has the victim approve a real Microsoft device-code session, giving access without ever needing to steal or guess credentials.

How did the attackers make the phishing page look legitimate?

The campaign used a trusted Google Sites wrapper and routed victims through multiple reputable platforms, including a Google redirector, an OCI API Gateway, and a Cloudflare-protected host, before reaching the final destination.

Who was targeted in this campaign?

The campaign targeted an unnamed regulated financial customer and reused the same landing page, subject pattern, and fake internal reference ID against multiple financial and insurance organizations on the same day.

Read the video transcript

You get an email: “Missed call – new voicemail.” Looks internal, says click to listen. That’s the whole trap. You click, and it opens a legit-looking Google Sites page, then bounces through a couple trusted links before landing on a Microsoft device-code prompt asking you to approve access. Here’s the twist: this “Kali365 Ringer” scam never steals your password. If you approve that Microsoft device code for a voicemail you didn’t start, you hand them live access to your account. If a voicemail or missed-call email ever leads to a Microsoft device-code prompt you didn’t initiate, stop and report it to security immediately, don’t approve anything.

Similar attacks