Voicemail Lure Drives Microsoft Device-Code Phish

The Hacker News · Medium sophistication
Last updated July 30, 2026

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page to appear legitimate. Victims were redirected through multiple trusted services and instructed to approve a Microsoft device-code login session, giving attackers access without stealing a password via a fake login page.

How the attack worked

The campaign, tracked as Kali365 Ringer, began with a voicemail-style notification telling the recipient they had a missed call and needed to review a message. This simple pretext gave the attacker a reason to push the user toward a link. Clicking through led to a page built on Google Sites, a legitimate hosting platform that gave the phishing content a familiar, trustworthy appearance rather than an obvious spoofed domain.

From there, the victim was redirected through a chain of well-known services, including a Google redirector and an OCI API Gateway, before landing on a Cloudflare-protected host controlled by the attacker. Rather than presenting a fake login form to harvest a password, the page instructed the user to authorize a Microsoft device-code session. Approving that prompt handed the attacker an active, authenticated session without ever touching the victim's password.

Why it succeeded

Several design choices made this lure effective:

  • A voicemail or missed-call theme creates a sense of missing something important, prompting quick action.
  • Using Google Sites as a wrapper avoids the visual red flags of an unfamiliar or misspelled domain.
  • Routing traffic through multiple reputable platforms before reaching attacker infrastructure adds legitimacy and can complicate detection.
  • Asking for device-code approval instead of a password sidesteps user training focused on spotting fake login pages.

What to watch for

Defenders and employees should be alert to a few consistent signals from this campaign:

  • Unexpected voicemail or missed-call notifications that push a login or approval action.
  • Login or authorization flows hosted on general-purpose site builders like Google Sites rather than a known corporate domain.
  • Multiple redirects through unrelated third-party services before reaching a final page.
  • Any Microsoft device-code prompt that appears without the user having initiated a sign-in themselves.

The same landing page, sender subdomain, subject pattern, and fake internal reference ID were reused across multiple financial and insurance organizations targeted on the same day, a pattern that security teams can use to detect and block related campaign infrastructure quickly.

Building resistance

Organizations, particularly in finance and insurance where this campaign concentrated, should reinforce a simple rule: never approve a Microsoft device-code or device login prompt that was not self-initiated. Employees should also be encouraged to verify unexpected voicemail or missed-call messages through known internal channels before clicking any embedded link. Because this technique bypasses traditional password-harvesting defenses, awareness training should specifically cover device-code approval flows, not just fake login pages, and staff should have a clear, fast path to report suspicious authorization requests to IT or helpdesk teams.

Key findings

  • ZeroBEC reported a real device-code phishing attack (“Kali365 Ringer”) targeting an unnamed regulated financial customer.
  • The lure used a “missed-call notification” and a “trusted Google Sites wrapper” before redirecting through multiple reputable platforms to the attacker infrastructure.
  • Users were instructed to approve an attacker-controlled Microsoft device-code session instead of entering credentials on a fake login page.
  • The same Google Sites landing page and subject pattern were reused to target multiple organizations on the same day.

Who’s being targeted

  • Commonly targeted roles: All employees (Microsoft 365 users), Finance and Accounting, Insurance operations, Helpdesk / IT support (triage of login-approval reports).
  • Affected industries: Financial services, Insurance, Regulated financial organizations.
  • Attack channels: email, website.
  • Impersonated: Internal voicemail/telephony service (voicemail notification) using Google Sites as a trusted wrapper.

Red flags to watch for

  • Voicemail/missed-call message pushes you to sign in or approve access unexpectedly
  • Legitimate-looking Google Sites page used as a wrapper for login/authorization flow
  • Multiple redirects through well-known services before reaching the final destination
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Kali365 Ringer attack?

Kali365 Ringer is a device-code phishing campaign identified by ZeroBEC that used a fake missed-call voicemail notification to lure users toward approving an attacker-controlled Microsoft login session.

Why is device-code phishing dangerous?

Instead of stealing a password on a fake login page, the attacker has the victim approve a real Microsoft device-code session, giving access without ever needing to steal or guess credentials.

How did the attackers make the phishing page look legitimate?

The campaign used a trusted Google Sites wrapper and routed victims through multiple reputable platforms, including a Google redirector, an OCI API Gateway, and a Cloudflare-protected host, before reaching the final destination.

Who was targeted in this campaign?

The campaign targeted an unnamed regulated financial customer and reused the same landing page, subject pattern, and fake internal reference ID against multiple financial and insurance organizations on the same day.

Read the video transcript

You get an email: “Missed call – new voicemail.” Looks internal, says click to listen. That’s the whole trap. You click, and it opens a legit-looking Google Sites page, then bounces through a couple trusted links before landing on a Microsoft device-code prompt asking you to approve access. Here’s the twist: this “Kali365 Ringer” scam never steals your password. If you approve that Microsoft device code for a voicemail you didn’t start, you hand them live access to your account. If a voicemail or missed-call email ever leads to a Microsoft device-code prompt you didn’t initiate, stop and report it to security immediately, don’t approve anything.

Similar attacks

ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026