New Phishing Campaign Impersonates Google, Delivers Fake Audio Message
Key Takeaways A new phishing campaign is impersonating Google services, using fake audio message notifications to trick users. The attacks employ a multi-stage redirect chain, leveraging legitimate...
Key Takeaways
- A new phishing campaign is impersonating Google services, using fake audio message notifications to trick users.
- The attacks employ a multi-stage redirect chain, leveraging legitimate tracking services before leading to a convincing Google sign-in page.
- The phishing pages are designed to harvest credentials for Google Workspace or Google Voice accounts.
- Stolen credentials could grant attackers access to sensitive data, contacts, and enable further spear-phishing attacks.
Sophisticated Phishing Campaign Leverages Fake Audio Messages to Steal Google Credentials
Cybersecurity researchers have uncovered a new credential phishing campaign that skillfully mimics Google’s communication style, luring unsuspecting users with deceptive “New Audio MSG” emails. This campaign is designed to steal account credentials by directing targets to highly convincing, Google-themed sign-in pages.
Table Of Content
Instead of relying on suspicious attachments, the attackers employ a straightforward “Play Audio” call to action, making the initial email appear innocuous. This tactic capitalizes on the common expectation of receiving voicemail notifications, turning a routine prompt into a mechanism for credential theft.
The Deceptive Redirect Chain
The phishing emails initiate a complex tracking and redirect process. Upon clicking the “Play Audio” link, victims are routed through a series of intermediate services before finally arriving at a page meticulously crafted to resemble legitimate Google Workspace or Google Voice login portals. This layered approach is critical to the campaign’s success, as it makes the initial click seem benign, masking the malicious destination that ultimately harvests credentials outside of Google’s control.
According to Anurag said in a report shared with Cyber Security News (CSN), the recipient’s email address is encoded and carried through this redirect chain. This allows the attackers to personalize the final phishing page, pre-filling the email field or tailoring the display to the individual target, thereby enhancing the illusion of legitimacy. A detailed analysis of this Google-themed credential phishing attempt is available in this report.
The severity of this campaign stems from the potential compromise of work email accounts. A stolen login can unlock a trove of sensitive information, including files, contacts, and calendar entries, and can be used to reset passwords for other services. Furthermore, a compromised, trusted account can serve as a launchpad for more credible and targeted phishing attempts against colleagues, partners, or customers.
Technical Underpinnings of the Attack
The lure is crafted to exploit both urgency and familiarity. A user expecting a voicemail might instinctively click “Play Audio” without realizing the malicious intent. The link, however, first directs through email delivery and cloud tracking services before presenting a convincing Google login page.
Researchers noted the presence of a Base64-encoded version of the recipient’s email address within the URL fragment. While Base64 encoding obscures the text at a glance, it does not provide cryptographic protection. This encoded address is passed between stages, allowing the fake login page to dynamically display or target the specific email address, further increasing its perceived legitimacy. The final phishing page is designed to appear highly credible within the browser, utilizing a Blob URL for a Google Accounts-themed interface while fetching the actual phishing content from separate, attacker-controlled infrastructure. This multi-step process mirrors tactics observed in prior Gmail redirect campaigns, where an initial benign-looking hop concealed the true, malicious destination.
What You Should Do
- Verify Unexpected Audio Notifications: Never click on “Play Audio” links in unexpected email notifications. Instead, navigate directly to your voicemail service or Google Workspace/Voice portal through your browser to check for actual messages.
- Inspect URLs Carefully: Before entering any credentials, always scrutinize the URL in your browser’s address bar. Look for legitimate Google domains and secure HTTPS connections. Be wary of unusual or mismatched domains.
- Enable Multi-Factor Authentication (MFA): Implement MFA on all critical accounts, especially Google Workspace and Google Voice. MFA adds a crucial layer of security, making it significantly harder for attackers to access accounts even with stolen passwords.
- Report Suspicious Emails: Forward any suspicious “New Audio MSG” emails or similar phishing attempts to your IT security team or email provider for analysis and quarantine.
- Enhance Security Awareness Training: Educate employees that a legitimate voicemail notification should play audio or direct to a voicemail portal, not demand a password. Highlight the dangers of redirect chains and personalized phishing attempts.
- Monitor for Unusual Login Attempts: Security teams should monitor email telemetry for abnormal redirect patterns and correlate URL clicks with new login attempts. Block confirmed malicious domains and URLs at the email, web, and DNS layers.
Redirect Chains Complicate Detection
The use of seemingly reputable delivery or tracking infrastructure, such as sendgrid[.]net and rdnjfgli.r.ap-northeast-1.awstrack[.]me, is a deliberate tactic. Attackers often leverage these intermediary services because security filters and users tend to focus on the initial visible domain, which may appear legitimate. This pattern has been observed in other Google service abuse reports, where trusted-looking paths lend credibility to fraudulent messages.
Security teams must review email telemetry for unusual redirect patterns, particularly those originating from messages promising audio playback but leading to account sign-in prompts. They should correlate URL clicks with new login attempts, meticulously preserve the full redirect chain for forensic investigation, and proactively block confirmed malicious destinations across email, web, and DNS layers. August 11, 2026, an image illustrating the phishing attempt was shared.
This campaign underscores that branding alone is insufficient proof of legitimacy. A polished sign-in screen, a recognizable logo, and even a personalized email address can all be easily replicated by cybercriminals. Users must treat all unexpected authentication requests with extreme skepticism, even when the page appears familiar or follows a seemingly ordinary message. Defenders can reinforce awareness training with a simple principle: a legitimate voicemail notification should play audio, not demand a password. Teams investigating these events can also benefit from tracking the evolving landscape of AI-assisted email deception, which increasingly enables campaigns to bypass both human scrutiny and automated defenses.
Security personnel should also scrutinize messages that contain shortened or mismatched display links, and verify that the sender, subject, and destination align with normal business workflows. A quick verification via a known phone number or by directly opening the service in a new browser session can prevent a hasty click from escalating into an account compromise.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | sendgrid[.]net | Email delivery and tracking infrastructure observed in the redirect chain |
| Domain | rdnjfgli.r.ap-northeast-1.awstrack[.]me | Click-tracking domain used by the Play Audio link |
| URL | gm2.drr[.]accoderkubes[.]com/workspace/googlev.html | Google Workspace-themed phishing page |
| Domain | spy.mwork801[.]com | External phishing infrastructure |
| URL | spy.mwork801[.]com/gmail/js/start.js | JavaScript resource loaded by the phishing kit |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.