started · updated
Check Point Research detects massive voicemail transcript phishing campaign
Check Point Research has identified a large-scale phishing campaign that targets organizations by impersonating automated voicemail transcript notifications. Between August 17 and August 31, researchers detected more than 58,000 malicious emails targeting over 7,800 organizations globally.
The attackers utilize a sophisticated spoofing technique where the sender address is manipulated to match the recipient's own organization domain, making the emails appear as legitimate internal alerts. The subject lines typically follow a pattern starting with ‘Automated transcript’, followed by a partially obscured phone number and a random string.
Instead of traditional executables, the campaign uses Scalable Vector Graphics (.svg) files as attachments. These files contain embedded code that, when opened, redirects the user to a fraudulent login page. To increase the credibility of the theft, the phishing site often features the victim's email address already pre-filled in the authentication form. The campaign leverages over 38,400 spoofed sender addresses and more than 9,300 fraudulent domains to bypass conventional security filters.
Entities
Check Point Research · Check Point Software Technologies Ltd.