Office 365 users targeted with fake voicemail alerts in suspected whaling campaign - Help Net Security

Office 365 users targeted with fake voicemail alerts in suspected whaling campaign - Help Net Security

Office 365 users at high-profile companies in a wide variety of industries are being targeted with voicemail-themed phishing emails, McAfee researchers have found.


They say that a wide range of employees have been targeted, from middle management to executive level staff, and that these emails could be part of a “whaling” campaign.


The deception


The malicious emails take the form of (fake) Microsoft-branded notifications telling recipients of a missed call.


They contain an attachment: an HTML file that, when loaded, shows potential victims to a page that:


Autoplays a file that sounds like a truncated, recorded voice message
Tells them to wait while the entire voice message is downloaded from the server
Instructs them to log in to access the message.


< ..

Support the originator by clicking the read the rest link below.