Google-Themed Phishing Campaign Uses Fake 'New Audio MSG' Emails to Steal Credentials
A new phishing campaign is distributing fake "New Audio MSG" emails that lead users to a credential-harvesting page disguised as a legitimate Google sign-in portal.

A sophisticated phishing campaign is currently targeting users with deceptive emails that mimic audio message notifications. These emails, bearing the subject "New Audio MSG," prompt recipients to click a "Play Audio" link. Instead of playing a voicemail, this link initiates a complex tracking and redirect chain designed to obscure the malicious intent and deliver a fake Google sign-in page.
The campaign leverages a multi-stage approach to bypass initial security filters and build user trust. The initial email appears innocuous, playing on the common expectation of receiving voicemails. However, the "Play Audio" link is engineered to first pass through reputable email delivery and cloud tracking services. This tactic helps the phishing messages evade detection by security software that might flag direct links to suspicious domains.
Researchers have observed that the redirect chain encodes the recipient's email address in the URL using Base64. This personalized data is then carried through the subsequent steps, allowing the final phishing page to be tailored to the specific victim. This personalization significantly enhances the credibility of the fake sign-in page, making it more likely that users will enter their credentials.
The ultimate destination is a page meticulously designed to resemble Google Workspace or Google Voice login interfaces. By using a convincing visual replica of a legitimate Google sign-in page, attackers aim to trick users into divulging their account credentials. The use of Blob URLs and separate infrastructure for phishing content further complicates detection efforts, mirroring techniques seen in previous Gmail-based redirect campaigns.
The impact of such a campaign can be severe, particularly for work-related accounts. Compromised email credentials can grant attackers access to sensitive files, contacts, calendars, and even facilitate password reset mechanisms. Furthermore, a compromised trusted account can be weaponized to send more convincing phishing lures to colleagues, partners, or customers, expanding the attack's reach.
Security experts advise users to exercise extreme caution with unexpected audio notification emails. The recommended approach is to bypass any links provided and instead navigate directly to the relevant service (e.g., Google Workspace) through a known, legitimate browser session. Users should verify the existence of any real voicemails through official channels and always inspect the URL in the address bar before entering any login information.
Organizations are urged to bolster their defenses by monitoring email telemetry for unusual redirect patterns, especially those involving promised audio playback leading to authentication prompts. Correlating URL clicks with subsequent login attempts, preserving full redirect chains for analysis, and blocking confirmed malicious destinations at the email, web, and DNS layers are crucial mitigation steps. This campaign underscores the importance of security awareness training that emphasizes treating all unexpected authentication requests with suspicion, regardless of how familiar or legitimate the presented page may appear.