SVG voicemail phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and follow-on compromise. Attackers used SVG attachments disguised as voicemail files to smuggle obfuscated JavaScript past filters. The campaign ran in waves from June 1 through August 4, 2026, and was still active when the analysis closed.
Related Happenings
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
Campaign
H score16
First: 20.08.2026 22:59
Last: 20.08.2026 22:59
Sources 1
About this happening:
A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign
CampaignAbout this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
UAT-11764 QR code phishing campaign against organizations
Campaign
H score29
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
UAT-11764 QR code phishing campaign against organizations
CampaignAbout this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Timeline
-
28.08.2026 16:00 1 articles · 1h ago
Campaign spikes to 2,432 messages across 1,149 organizations
Campaign Scope UpdateOn June 3, 2026, the phishing campaign reached its largest daily spike, with 2,432 messages delivered to 1,149 organizations, reinforcing a broad spray pattern rather than a tightly focused spear-phishing effort.
Show sources
- Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign — www.infosecurity-magazine.com — 28.08.2026 16:00
-
27.08.2026 16:00 2 articles · 1d ago
INKY publishes analysis of SVG voicemail phishing campaign
Technical Analysis UpdateOn August 27, 2026, INKY published technical findings on a two-month phishing campaign that ran from June 1 through August 4, 2026, used SVG attachments disguised as voicemail files to deliver obfuscated JavaScript, and was detected and flagged by INKY/Kaseya. The analysis also noted internal sender impersonation, MIME-type deception, and low Microsoft Spam Confidence Level scores that let many messages appear harmless.
Show sources
- Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign — www.infosecurity-magazine.com — 28.08.2026 16:00
- Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign — www.infosecurity-magazine.com — 28.08.2026 16:00