{"id":416947,"date":"2026-09-20T14:31:36","date_gmt":"2026-09-20T14:31:36","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=416947"},"modified":"2026-09-20T14:31:36","modified_gmt":"2026-09-20T14:31:36","slug":"orax-voicemail-phishing-sessions-after-mfa","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/orax-voicemail-phishing-sessions-after-mfa\/","title":{"rendered":"ORAX Voicemail Phishing Steals Sessions After MFA"},"content":{"rendered":"<p>An email says a new voicemail is waiting. It comes from a legitimate account, passes through familiar marketing services, and offers a simple \u201cListen To Message\u201d button.<\/p><div id=\"mwtad303009883\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>After a human-check page, the recipient reaches a Google sign-in screen. The password works, the multi-factor prompt arrives, and the sequence appears to behave like a real login.<\/p>\n<p>The page is coordinating with an attacker in real time. Completing MFA can hand over a reusable Google Workspace session, even though the victim never intentionally approved a new device.<\/p><div id=\"mwtad1243500112\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416948 lazyload\" alt=\"ORAX voicemail phishing email with a Listen To Message button\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-1-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-1-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-1-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-1-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad491459271\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A voicemail lure reached hundreds of organizations<\/h3>\n<p>ORAX is a phishing-as-a-service platform documented by Abnormal Intelligence. One observed campaign sent about 12,846 fake voicemail messages from a compromised nonprofit bulk-mail account to employee mailboxes at 675 US organizations.<\/p>\n<p>The targeting crossed software, education, finance, media, retail, manufacturing, technology, and business services. The broad distribution shows a mass campaign rather than one person complaining about an isolated email.<\/p>\n<h3>Multiple trusted services lead to a fake Google login<\/h3>\n<p>The \u201cNew VM Received\u201d email sends the victim through a Mailchimp click tracker to a Brevo-hosted landing page. An emoji CAPTCHA or anti-analysis gate tries to separate real people from automated security scanners.<\/p><div id=\"mwtad702391141\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>After another challenge, ORAX displays its own copy of a Google sign-in page. Google does not host or control that page, even though the prompts are synchronized with a real authentication attempt behind the scenes.<\/p>\n<h3>The target is the authenticated session, not only the password<\/h3>\n<p>ORAX keeps the phishing page connected to its backend through WebSockets. When the victim enters a password or responds to an MFA challenge, the platform advances the real login and updates the copied page in real time.<\/p>\n<p>If authentication succeeds, the attacker can capture the resulting Google Workspace session. That access may support business email compromise, mailbox-rule abuse, internal phishing, and financial fraud.<\/p><div id=\"mwtad3779119522\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>The campaign begins with a fake voicemail notification.<\/li>\n<li>A compromised legitimate bulk-mail account helps the message look familiar.<\/li>\n<li>Mailchimp and Brevo infrastructure are abused during delivery.<\/li>\n<li>An emoji CAPTCHA or encrypted gate blocks automated analysis.<\/li>\n<li>The final Google sign-in page is built and controlled by ORAX.<\/li>\n<li>A persistent WebSocket synchronizes prompts with the attacker\u2019s backend.<\/li>\n<li>Password and MFA responses are relayed through a real authentication attempt.<\/li>\n<li>The attacker\u2019s objective is a reusable authenticated session.<\/li>\n<\/ul>\n<div id=\"mwtad1043838599\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Successful MFA Does Not Prove the Page Is Real<\/h2>\n<p>Many people have learned that an unexpected sign-in without MFA is dangerous. ORAX exploits the next assumption: if the correct password is accepted and the phone shows a real verification prompt, the browser page must be legitimate.<\/p>\n<p>The prompt can be real because the attacker is initiating a real Google authentication session at the same moment. The victim supplies each answer through the copied page, while ORAX passes the process forward and mirrors the next challenge.<\/p>\n<div id=\"mwtad2373596593\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>This is an adversary-in-the-middle outcome, but ORAX does not rely on the traditional reverse-proxy design used by many phishing kits. Its page stays connected to the platform and receives instructions about what field or challenge to show next.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416949 lazyload\" alt=\"ORAX emoji CAPTCHA gate used to filter security scanners before phishing\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-2-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-2-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-2-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-2-final-1024x576.png 1024w\"><\/figure>\n<p>The first CAPTCHA strengthens the illusion. A rotating emoji puzzle feels like a security measure protecting a private voicemail, yet its real purpose is to keep automated URL scanners and headless browsers away from the credential harvester.<\/p>\n<p>One alternate gate decrypts itself in the browser and checks for automation, proxies, or developer tools. Target-facing domains can disappear quickly; Abnormal found one harvester domain that expired a day after its lure was sent.<\/p>\n<div id=\"mwtad1333270109\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The safest clue remains the final address bar. A Google sign-in must be on a genuine Google-controlled domain. A correct-looking page, working password, or authentic phone prompt cannot substitute for that domain check.<\/p>\n<div id=\"mwtad3483992202\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>A legitimate sender account can still be compromised<\/h3>\n<p>The observed campaign used a hijacked nonprofit bulk-mail account and followed its contact list. Authentication checks may therefore show a message traveling through real mailing infrastructure.<\/p>\n<p>That proves which account sent the email, not that the account owner intended it. An unexpected voicemail should be verified through the organization\u2019s known phone or messaging system.<\/p>\n<h3>Mailchimp, Brevo, and Cloudflare are delivery layers<\/h3>\n<div id=\"mwtad2585273869\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>ORAX abuses trusted services for click tracking, landing pages, and challenges. Their presence can help the chain evade simple domain blocks, but none of them validates the voicemail claim.<\/p>\n<p>Follow every redirect mentally to the final destination. If the login page is not on Google\u2019s real domain, close it regardless of the services used earlier.<\/p>\n<h3>MFA codes and approvals can be relayed<\/h3>\n<p>One-time codes, phone prompts, and some push approvals confirm that someone is completing a login. They do not automatically bind that login to the browser page the victim is viewing.<\/p>\n<p>FIDO2 security keys and properly deployed passkeys are stronger because they are cryptographically tied to the legitimate site. They should not authenticate an unrelated phishing domain.<\/p>\n<h3>Independent research confirms the ORAX campaign<\/h3>\n<p><a href=\"https:\/\/abnormal.ai\/blog\/orax-aitm-phishing-without-reverse-proxy\" rel=\"noopener noreferrer\" target=\"_blank\">Abnormal Intelligence documented the campaign volume, compromised sender, filtering gates, WebSocket architecture, live challenge synchronization, and session-theft objective<\/a>. Researchers observed ORAX infrastructure from about February through mid-August 2026.<\/p>\n<p>Abnormal assessed with moderate confidence that an Iran-nexus developer operates the platform. That attribution is an assessment about the developer, not proof that every campaign customer or victim has the same location.<\/p>\n<div id=\"mwtad3984175403\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the ORAX Voicemail Phishing Scam Works<\/h2>\n<h3>Step 1: A compromised account sends the voicemail lure<\/h3>\n<p>The recipient gets an email with a subject such as \u201cNew VM Received.\u201d The message claims a recording is available and includes a button to listen.<\/p>\n<p>Because the sender account is legitimate but compromised, the message may pass checks that would expose a newly created spoofing domain. The campaign can also inherit a real contact list.<\/p>\n<h3>Step 2: Marketing links lead to a voicemail landing page<\/h3>\n<p>The button passes through a Mailchimp tracker and reaches a Brevo or Convrrt page on a sibpages.com subdomain. The page repeats the voicemail story and invites another click.<\/p>\n<p>These services are legitimate. The attacker is using their free or existing infrastructure as stepping stones.<\/p>\n<h3>Step 3: A gate tries to exclude scanners<\/h3>\n<p>The next page may ask the visitor to select three matching emoji icons. The set changes on each request, making simple automated replay less useful.<\/p>\n<p>Another version checks for headless browsing, WebDriver, a proxy, or developer tools. A real user is passed through a one-time token and another managed challenge.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416950 lazyload\" alt=\"Fake Google Workspace login synchronized by ORAX to steal an authenticated session\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-3-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-3-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-3-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/orax-voicemail-phishing-sessions-after-mfa-3-final-1024x576.png 1024w\"><\/figure>\n<h3>Step 4: ORAX displays its own Google sign-in copy<\/h3>\n<p>The harvester is not Google\u2019s live page passed through a proxy. It is an attacker-built interface connected to the ORAX backend.<\/p>\n<p>The victim enters an email address and password. ORAX sends commands such as Input and Submit while the operator\u2019s process advances a real authentication flow.<\/p>\n<h3>Step 5: The phishing page mirrors the MFA challenge<\/h3>\n<p>If Google requests another factor, ORAX uses its Challenge and MirrorChallenge logic to update the victim\u2019s page. SignalR and WebSockets keep the correct target matched to the correct live session.<\/p>\n<p>The victim may receive a genuine push, code, or phone prompt and approve it. That response is being used to finish the attacker-controlled login.<\/p>\n<h3>Step 6: The authenticated session is captured and reused<\/h3>\n<p>Once MFA succeeds, the operator obtains reusable session access. The password and factor have done their job, but the resulting session belongs to the attacker\u2019s workflow.<\/p>\n<p>The attacker can read mail, create forwarding or inbox rules, register persistence, send internal phishing, change payment instructions, or use trusted conversations for business email compromise.<\/p>\n<div id=\"mwtad621918499\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Session Theft Can Outlast the Phishing Page<\/h2>\n<p>A password is one secret used during authentication. A session token is proof that authentication already succeeded. Services use tokens so people do not need to enter a password and MFA response every time they open another message or browser tab.<\/p>\n<p>ORAX aims to capture that authenticated state. The phishing domain may disappear the next day, but a stolen session can remain useful until it expires or an administrator revokes it.<\/p>\n<p>Changing the password is still essential because the attacker saw it. However, some existing sessions and refresh tokens may continue until the provider\u2019s account controls invalidate them. A complete response explicitly signs out sessions and forces fresh authentication.<\/p>\n<p>Mailbox rules are a common persistence method. An attacker can forward selected mail, hide security alerts, move invoices to another folder, or delete replies that might warn the victim. Review rules and delegates even when the inbox looks normal.<\/p>\n<p>OAuth grants create another path. A malicious or attacker-approved application may retain access through its own authorization. Remove unfamiliar connected applications and consent grants rather than focusing only on devices.<\/p>\n<p>Finally, check sent and deleted mail. ORAX access is valuable because the compromised account can contact coworkers from a trusted identity. Fast warnings can stop a second employee from approving a payment or entering credentials into the same campaign.<\/p>\n<p>Workspace administrators should correlate the reported login time with IP addresses, devices, token issuance, and application consent. The unusual domain may be gone, but identity logs can still show where the captured session was used.<\/p>\n<p>Preserve those logs before routine retention removes them. They help distinguish a blocked attempt from a completed takeover and define which messages, files, or business processes require review.<\/p>\n<div id=\"mwtad2083148632\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Warning Signs in a Voicemail Login Email<\/h2>\n<ul>\n<li>The voicemail notice was not generated by your normal phone system.<\/li>\n<li>The subject is generic, such as \u201cNew VM Received.\u201d<\/li>\n<li>The button passes through several unrelated services and domains.<\/li>\n<li>A voicemail requires a CAPTCHA before playback.<\/li>\n<li>The page asks for a Google Workspace password to hear a recording.<\/li>\n<li>The final sign-in is not on a Google-controlled domain.<\/li>\n<li>Your password manager refuses to autofill the credentials.<\/li>\n<li>A sign-in prompt appears for a location or device you do not recognize.<\/li>\n<li>The page blocks developer tools or behaves differently through a security scanner.<\/li>\n<li>The message arrives from an unusual bulk-mail account or nonprofit contact.<\/li>\n<\/ul>\n<p>Do not approve an MFA prompt just because you started some form of sign-in. Read the service, device, location, and request details, and stop when they do not match what you intended.<\/p>\n<div id=\"mwtad3835588641\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>If you did not enter credentials, close the pages.<\/strong> Report the email as phishing and tell your organization\u2019s security team. Do not return to test the emoji gate.<\/li>\n<li><strong>Use a clean device to secure the account.<\/strong> Navigate directly to the official Google account or Workspace portal. Do not use links from the voicemail message.<\/li>\n<li><strong>Revoke all active sessions and refresh tokens.<\/strong> ORAX targets the authenticated session, so a password change by itself is not sufficient. Force reauthentication across devices.<\/li>\n<li><strong>Change the password.<\/strong> Create a unique replacement and update any other account that reused the exposed password. Check whether the attacker changed recovery details.<\/li>\n<li><strong>Audit multi-factor authentication.<\/strong> Remove unknown devices, security keys, phone numbers, app passwords, and backup methods. Replace recovery codes if they may have been exposed.<\/li>\n<li><strong>Inspect mailbox persistence.<\/strong> Look for forwarding addresses, inbox rules, delegates, OAuth grants, filters, sent messages, deleted alerts, and unfamiliar third-party applications.<\/li>\n<li><strong>Warn finance and close contacts.<\/strong> Attackers may send believable payment requests from the compromised mailbox. Verify recent changes to invoices, bank accounts, gift-card requests, and wire instructions by phone.<\/li>\n<li><strong>Scan endpoints and reduce repeat exposure.<\/strong> Malwarebytes can check for additional threats if files were downloaded. AdGuard can block known phishing destinations, but neither can revoke a stolen cloud session; that must be done in the account or by an administrator.<\/li>\n<li><strong>Preserve and report evidence.<\/strong> Save the original email, headers, redirect chain, final domain, login time, MFA prompt, and account logs. Report the incident to IT, the mail provider, and the relevant fraud authority.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is ORAX?<\/h3>\n<p>ORAX is a phishing-as-a-service platform that synchronizes a fake sign-in page with a real authentication attempt to capture MFA-authenticated Google Workspace sessions.<\/p>\n<h3>Was Google Workspace breached?<\/h3>\n<p>The research describes phishing and authentication abuse, not a breach of Google\u2019s systems. Victims are sent to an attacker-controlled page on unrelated infrastructure.<\/p>\n<h3>Why did my real MFA prompt appear?<\/h3>\n<p>The attacker was advancing a real login using the information entered on the phishing page. The genuine prompt authorized that attacker-controlled session.<\/p>\n<h3>Is changing my password enough?<\/h3>\n<p>No. Revoke all active sessions and refresh tokens, force reauthentication, change the password, and inspect the account for persistence such as forwarding rules and OAuth grants.<\/p>\n<h3>Can passkeys stop this type of attack?<\/h3>\n<p>Properly deployed FIDO2 security keys and passkeys are phishing-resistant because authentication is bound to the legitimate site. One-time codes and push approvals can still be relayed.<\/p>\n<h3>Does a Mailchimp or Brevo link make the email safe?<\/h3>\n<p>No. Both are legitimate services that can be abused through compromised accounts or attacker-created pages. Check the final destination and verify the voicemail independently.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>ORAX voicemail phishing is a confirmed mass campaign built to steal more than a Google password. It coordinates a live login so the attacker can take the authenticated session after MFA succeeds.<\/p>\n<p>A working password and a genuine phone prompt do not validate the page in front of you. The final domain must belong to Google, and an unexpected voicemail should never dictate where you sign in.<\/p>\n<p>If you completed the flow, revoke sessions and tokens before assuming a password change solved it. Then audit the mailbox for rules, grants, and messages the attacker may have created.<\/p>\n<div id=\"mwtad1898663358\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An email says a new voicemail is waiting. It comes from a legitimate account, passes through familiar marketing services, and offers a simple \u201cListen To Message\u201d button. After a human-check page, the recipient reaches a &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"ORAX Voicemail Phishing Steals Sessions After MFA\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/orax-voicemail-phishing-sessions-after-mfa\/#more-416947\" aria-label=\"Read more about ORAX Voicemail Phishing Steals Sessions After MFA\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":416948,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-416947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=416947"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416947\/revisions"}],"predecessor-version":[{"id":417205,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416947\/revisions\/417205"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/416948"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=416947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=416947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=416947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}