CyberSecurityNews

Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email


A new credential phishing campaign is using a fake “New Audio MSG” email to draw recipients toward a convincing Google-themed sign-in page.

The message turns a familiar voicemail-style prompt into a way to steal account credentials, relying on a simple Play Audio call to action rather than a suspicious attachment.

The email sends its target through a tracking and redirect chain before presenting a page made to resemble Google Workspace or Google Voice.

That layered route can make the first click appear routine while moving the victim toward a credential-harvesting site controlled outside the legitimate service.

Anurag said in a report shared with Cyber Security News (CSN) that a recipient’s email address is encoded and carried through the redirect process, helping the operators prepare the later page for that individual.

The campaign matters because work email accounts can expose far more than messages.

A stolen login may open access to files, contacts, calendars and reset links, while a trusted account can be reused to send more believable lures to colleagues, partners or customers.

Google-themed Credential Phishing Attempt

The lure is built around urgency and familiarity. A recipient who expects a voicemail may see “New Audio MSG,” click Play Audio and assume they are opening a harmless recording.

Instead, the link first uses email-delivery and cloud tracking services, then passes the browser to a page that imitates a Google login experience.

Researchers observed a Base64-encoded copy of the recipient’s email address in the URL fragment.

In simple terms, Base64 is a way of representing text that can conceal its meaning at a glance, not a form of protection. Carrying that value between steps can let the fake page recognize which address it should display or target.

The final stage is designed to look more credible in the browser. It creates a Google Accounts-themed page with a Blob URL, then obtains the phishing content from separate infrastructure.

This use of several steps echoes techniques seen in earlier Gmail redirect campaigns, where a benign-looking first hop concealed the destination.

For an employee, the safest response is to avoid using a link in an unexpected audio notification.

Open the usual service directly in a browser, verify whether a real voicemail exists, and inspect the address bar before entering any password.

Organizations should also report and quarantine similar emails so other inboxes can be checked quickly.

Redirect Chains Complicate Detection

The use of reputable delivery or tracking infrastructure does not make the final destination safe.

Attackers often choose intermediary services because filters and users may focus on the first visible domain.

A similar pattern appeared in Google service abuse reports, where trusted-looking paths helped fraudulent messages gain credibility.

Security teams should review email telemetry for unusual redirect patterns, particularly messages that promise audio playback but lead to account sign-in prompts.

They should correlate URL clicks with new login attempts, preserve the full redirect chain for investigation, and block confirmed malicious destinations at the email, web and DNS layers.

This case also shows why branding alone is not proof of legitimacy. A polished sign-in screen, a recognizable logo and a personalized address can all be copied by criminals.

Readers should treat unexpected authentication requests as suspicious, even when the page appears familiar or arrives after a seemingly ordinary message.

Defenders can strengthen awareness training with a simple test: a voicemail notification should play audio, not demand a password.

Teams investigating these events may also benefit from tracking AI-assisted email deception, which shows how campaigns are increasingly built to evade both human review and automated analysis.

Security staff can also monitor messages that use shortened or mismatched display links, and review whether the sender, subject and destination match normal business workflows.

A quick verification through a known phone number or a new browser session can stop a rushed click from becoming an account compromise.

Indicators of comromise (IoCs):-

TypeIndicatorDescription
Domainsendgrid[.]netEmail delivery and tracking infrastructure observed in the redirect chain
Domainrdnjfgli.r.ap-northeast-1.awstrack[.]meClick-tracking domain used by the Play Audio link
URLgm2.drr[.]accoderkubes[.]com/workspace/googlev.htmlGoogle Workspace-themed phishing page
Domainspy.mwork801[.]comExternal phishing infrastructure
URLspy.mwork801[.]com/gmail/js/start.jsJavaScript resource loaded by the phishing kit

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





Source link