Phishing email attacks are not new issues but they are growing in sheer number as phishing scammers keep bringing up new ways to trick their targets. In a new phishing campaign reported by Bleeping Computer, Microsoft OneNoteAudio Note is used as a brand impersonation tactic to lure email recipients into disclosing their login credentials.

This campaign starts with an email titled “New Audio Note Received” stating that a contact in the address book has sent you a new audio note. If you clickthe hyperlinked “LISTEN TO FULL MESSAGE HERE”, you will be directed to a fake OneNote web page hosted on

On this page, you are again urged to click another link to get the audio message you want. This link brings you to a look-alike but counterfeit Microsoft login page that is waiting to steal your account credentials.

It is worth mentioning that the cybercriminals even “gently” remind you in the footer notes that this email was scanned by an antivirus software. Attackers also get a legitimate certificate signed by Microsoft as the phishing pages are hosted on These tactics are designed to make the phishing email indistinguishable by users.

Email Isolation Technology specially designed for Phishing Attack

