A new phishing campaign uses a fake "New Audio MSG" email to lure recipients into a Google-themed sign-in page, tricking them into sharing their credentials. According to Anurag's report shared with ZeroOwl (ZeroOwl), an encoded email address is passed through the redirect process, allowing attackers to tailor the final page to the target's interests. A stolen login might allow access to files, contacts, calendars, and reset links, while a trusted account could be reused to send more convincing phishing attempts to colleagues, partners, or customers.

The lure aims for urgency and familiarity by mimicking the sound of an incoming voicemail with “New Audio MSG.” Instead, it uses email-delivery and cloud tracking services to trick users into clicking on a link that redirects them to a Google login page, where they might enter their credentials unknowingly. This complicates detection efforts.

Indicators of compromise (IoCs): - **Domain**: sendgrid[. ]net - Observed in redirect chains - **Domain**: rdnjfgli.r.ap-northeast-1.awstrack[. ]me - Click-tracking domain used by the Play Audio link - **URL**: gm2.drr[.]accoderkubes[.

]com/workspace/googlev.html - Google Workspace-themed phishing page - **Domain**: spy.mwork801[. ]com - External phishing infrastructure - **URL**: spy.mwork801[. ]com/gmail/js/start.js - JavaScript resource loaded by the phishing kit Integrate real-time threat intelligence from trusted sources like MISP, VirusTotal, or your Security Information and Event Management (SIEM) system to proactively prevent phishing attacks and malware infections.