In early 2025, threat actors began exploiting a novel twist on voice phishing—embedding deceptive prompts within familiar multimedia formats to outmaneuver traditional security defenses. By disguising malicious content as routine audio or video files, attackers manipulate trust to trigger call-based scams, steering victims toward counterfeit support hotlines under the guise of legitimacy.

Emerging Multimedia-Based Vishing Tactics: A New Psychological Playbook
Recent threat intelligence reveals a sharp pivot in vishing strategies, where attackers now favor visually rich multimedia lures over traditional text-heavy emails. These campaigns typically arrive as nearly blank emails—deliberately vague to spark curiosity—accompanied by audio or video attachments that simulate billing alerts or account notifications.
Once the file is opened, the user is presented with a convincingly branded message—often mimicking PayPal or similar trusted platforms—warning of suspicious transactions or urgent payment issues. The visuals are crafted to mirror legitimate communications, complete with logos and formatting, pressuring recipients to call a prominently displayed “support” number within 24 hours.
Uncovered in January 2025 by Trellix, this campaign marks a departure from the usual use of static PDFs, signaling an evolution toward immersive deception. Their telemetry indicates that nearly 4 out of 5 attacks use PayPal as the bait, while the rest imitate IT support teams or broadly finance-themed entities.
The multi-stage psychological manipulation is key: ambiguity in the initial email sparks engagement, the multimedia message escalates anxiety, and the final phone interaction exploits urgency and fear to extract personal or financial details. This layered approach blends visual misdirection with real-time coercion, raising the bar for both detection and defense.

Anatomy of a Modern Multimedia Vishing Scheme
A new wave of multi-layered voice phishing campaigns is outperforming legacy phishing tactics by exploiting overlooked gaps in email security infrastructure.
Slipping Past Defenses: The Role of Multimedia Decoys
One reason these campaigns evade detection so effectively lies in their choice of file formats. Rather than relying on PDFs or malicious scripts, attackers are embedding fake billing visuals inside MP4 and WebP files—formats that rarely raise red flags during automated scans. These multimedia files aren’t what they appear to be. Instead of playing a video or showing a complex image, they display static frames crafted to mimic legitimate invoices or alert messages.
In the case of files labeled “Invoice QCFT-01031D15.mp4” and “ASIF_page-0001 (1).webp,” Trellix researchers uncovered that the payload consisted solely of fraudulent static payment content masquerading as multimedia. This trick enables attackers to bypass filtering systems that deprioritize non-executable, low-risk formats—creating a significant blind spot.
Strategic Evasion Meets Psychological Manipulation
By combining technically benign file types with emotionally charged content, these campaigns minimize security scrutiny while maximizing user engagement. The process works in stages: a vague email triggers curiosity, a multimedia attachment simulates a financial issue, and a fake support number urges immediate action—closing the trap with a live voice interaction.
To counteract this emerging threat, experts advise organizations to extend content inspection policies to include less conventional file types and apply behavioral analysis to email context. Additionally, end-user training should now include awareness of these sophisticated, media-based social engineering schemes that exploit both trust and urgency.




