Multiple reports describe social-engineering-driven initial access where victims are coerced into executing attacker-supplied scripts rather than being exploited via a software vulnerability. The “Voicemail Trap” campaign uses fake voicemail notifications (often styled as routine business communications and sometimes impersonating financial entities) to drive targets to compromised, bank-themed web infrastructure that mimics an audio player and instructs users to download and run a Windows BAT file disguised as a media/codec update; researchers observed dozens of distinct web properties supporting the lure and the execution chain is designed to blend in as legitimate system maintenance while leveraging built-in administrative tooling to reduce AV detection.
Separately, an investigation attributed to BlueNoroff (a financially motivated subgroup of Lazarus) documented a macOS compromise that begins with outreach on messaging platforms (e.g., Telegram) and escalates into a Microsoft Teams call where the attacker claims an “audio issue” and coaches the victim to paste terminal commands that download and execute a payload. The malware is written to a benign-looking path such as /Library/Caches/com.apple.sys.receipt, then made executable (e.g., chmod 777) and ad-hoc signed to appear more legitimate and bypass some security checks; the targeting focus is professionals in cryptocurrency/financial sectors. A third item describes a Facebook paid-ads malvertising chain that redirects users through decoy sites to a tech-support scam kit and rotates domains rapidly, but it is a distinct campaign from the voicemail and fake-audio troubleshooting lures.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Daylight Security assessed the observed macOS tradecraft as consistent with the 'GhostCall' campaign pattern publicly attributed to BlueNoroff, a financially motivated subgroup of the Lazarus Group. The targeting focused on cryptocurrency and financial-sector professionals.
Daylight Security reported a macOS intrusion in which an attacker used messaging apps and a Microsoft Teams call, claiming an audio problem, to pressure a victim into pasting malicious Terminal commands. The activity was attributed to BlueNoroff and involved downloading a disguised payload, using living-off-the-land techniques, stealing credentials including the macOS Keychain, and deploying secondary persistence components.
Censys reported identifying the 'Voicemail Trap' social-engineering campaign on January 12, 2026, and observed 86 distinct web properties serving fake voicemail lures. The campaign used compromised, bank-themed subdomains to deliver a BAT script that installed the open-source RMM tool Remotely for persistent access.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.