A sneaky new phishing campaign targeting German speakers. Attackers are using fake voicemail notifications on 86 compromised websites to trick users into downloading a malicious BAT file.
This file installs Remotely RMM, a legitimate remote monitoring and management tool that has been hijacked for unauthorized access. First spotted on January 12, 2026, the tactic blends social engineering with technical deception to bypass user suspicion and defenses.
The campaign exploits everyday expectations. Victims land on pages mimicking routine voicemail alerts, complete with simple German text urging them to “listen to your new message.”
These pages look harmless no flashy graphics or urgent warnings just functional prompts that feel like a normal phone carrier notice. Clicking leads straight to malware execution, turning a quick check into a complete system compromise.
Attack Chain Breakdown
Censys researchers mapped the full infection flow, revealing a streamlined five-step process designed for high success rates.

- Voicemail Landing Page
- Compromised web properties host the lure. German phrasing like “Neue Sprachnachricht verfügbar” (New voicemail available) prompts users to play audio.
- Pages are minimal: a button, introductory text, and no red flags. English translations shared by Censys show how it mimics legit services. Over 86 such sites were active, scanned via Censys’ internet-wide monitoring.
- BAT File Delivery and Execution
- Interaction downloads “voicemail.bat,” disguised as an audio player update. Running it shows fake console output like “Updating media player…”
- It asks users to approve Windows security prompts, normalizing the behavior. This social engineering step conditions victims to click through UAC dialogs without alarm.
- Decoy Audio Playback
- The script downloads an audio file from AWS S3 and opens it in a minimized browser tab. The English-language clip plays an irrelevant voicemail script, hidden from view, that purports to provide “proof” the action worked. This multi-sensory trick reinforces legitimacy while malware runs silently.
- RMM Installation and Enrollment
- In parallel, the BAT deploys Remotely RMM a real, open-source tool from GitHub (github.com/immense/Remotely).
- It enrolls the victim machine to an attacker-controlled server at hxxps://remotely[.]billbutterworth[.]com/api/devices. Censys confirmed the C2 via certificate data: a self-signed cert tied to the domain, visible in their platform scans. The admin portal lets attackers monitor and control infected systems remotely.
- Post-Installation Access
- The RMM agent persists across reboots, granting operators full remote desktop access, file management, and command execution. Potential follow-ons include lateral movement, data theft, or ransomware drops though none observed yet.
- IOCs include the BAT hash (SHA-256; not specified in the initial report; monitor for variants), the C2 domain, and AWS-hosted audio.
.webp)
| Indicator Type | Details |
|---|---|
| C2 Domain | hxxps://remotely[.]billbutterworth[.]com/api/devices |
| Malware | voicemail.bat (delivered via landing pages) |
| Hosted Audio | AWS S3 buckets (e.g., specific URIs in script) |
| Tool | Remotely RMM (GitHub: immense/Remotely) |
| Affected Sites | 86 German-language web properties (Censys scan, 01/12/26) |
This threat highlights the dual-use risk of RMM tools legit for IT but deadly in the wrong hands. Enterprises should block unknown RMM installs via app allowlisting (e.g., Windows AppLocker) and monitor for anomalous processes.
.webp)
The simplicity is the genius: Voicemail feels urgent yet innocuous, evading email filters. As RMM abuse rises (seen in prior campaigns like MgBot), vigilance on cloud-hosted decoys and BAT droppers is key. Stay tuned for updates as Censys tracks variants.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.