A large-scale phishing campaign sent 26,589 fake voicemail emails to more than 5,500 organizations between June 1 and August 4, using malicious SVG attachments to evade email security controls. The broadly distributed, non-targeted messages impersonated internal senders, personalized subject lines with recipients’ email local parts, and were largely delivered in weekday waves.
The attachments were disguised as voicemail notifications and declared with the anomalous text/plain MIME type despite containing SVG/XML content. Embedded, obfuscated JavaScript used deferred execution and runtime script injection to retrieve remote content. Native Microsoft spam filtering assigned 75% of the messages Spam Confidence Level 0 or 1, classifying them as non-spam or low-confidence spam and allowing the campaign to bypass many standard defenses.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
INKY observed campaign waves through August 4, totaling 26,589 phishing messages across 5,527 organizations. Native Microsoft filtering assigned 75% of the messages Spam Confidence Level 0 or 1, treating them as non-spam.
The campaign's largest observed spike delivered 2,432 messages to 1,149 organizations.
A broad phishing campaign began using SVG attachments disguised as internal voicemail notifications. The attachments mislabeled active SVG/XML content as text/plain and concealed obfuscated JavaScript that fetched remote content.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.