DomainGuard

Threat Intel

FedEx Voicemail Phishing (Vishing)

A FedEx-themed vishing campaign that uses an automated voicemail to send victims through fake Cloudflare and hCaptcha checks to a cloned tracking page, which harvests personal details and credit card data over a live operator channel.

Cloned FedEx tracking page showing a fake failed delivery and a button to reschedule, hosted on an attacker-controlled domain.
Cloned FedEx tracking page showing a fake failed delivery and a button to reschedule, hosted on an attacker-controlled domain.
First Seen
2026
Status
Active in the wild

DomainGuard threat intel, published for defense. Security teams can use it to detect and block this technique; anyone who runs into it can use it to recognize the lure and stay safe. Indicators of compromise are defanged.

Vishing FedEx Package Delivery Scam Payment Fraud Fake CAPTCHA Phishing Kit 5 min read

What it is

FedEx voicemail phishing is a voice phishing, or vishing, campaign that impersonates the parcel carrier to steal payment card data. An automated voicemail claims there is a problem with a package’s delivery address and names a website to visit before a deadline. The site is a cloned FedEx tracking page that asks for a small redelivery fee.

Fake delivery-fee lures have run by text and email for years. Delivering one by voicemail sidesteps the filters built for those channels. The recording never names FedEx; the brand appears only in the domain, fedexwm[.]com, a brand-plus-suffix lookalike domain.

How it works

  1. Voicemail Lure. An automated message warns of an address problem and sets a deadline one day out. On iPhone, the voicemail transcript renders the spoken domain as a tappable link.

    Voicemail from the campaign, with the lookalike domain rendered as a tappable link in the transcript.
    Voicemail from the campaign, with the lookalike domain rendered as a tappable link in the transcript.
  2. Fake Cloudflare Gate. The lookalike domain serves only a Cloudflare-style checkbox asking the visitor to prove they are human. It is not Cloudflare: the page comes from a Python (Uvicorn) app behind a Caddy proxy, and the Ray ID is a random value generated in the browser. Unlike the ClickFix version of this lure, it asks only for a click, which is logged to /api/click_report before the victim is forwarded to a second domain.

    Fake Cloudflare-style verification page served on the lookalike FedEx domain.
    Fake Cloudflare-style verification page served on the lookalike FedEx domain.
  3. Fake hCaptcha. The second domain, dexalorin[.]shop, shows a mock hCaptcha checkbox drawn in SVG and CSS, with no call to the real service. Clicking it appends a session token (__eat) and reloads into the payload.

  4. Cloned Tracking Page. A FedEx-branded app shows a fake tracking number and a failed-delivery status. On load it opens a Socket.IO WebSocket to /console/, a live channel back to the operator’s panel typical of kits built for real-time fraud.

  5. Personal Data Harvest. The victim picks a new delivery window and enters their full name, street address, email, and phone number.

  6. Card Harvest. A payment page, citing a supposed FedEx policy, charges $1.20 for redelivery and asks for the card number, expiry, and CVV. A test card drew an error asking for a different card, on a button that misspells “another”. The fee is a pretext; the card, and ideally a second one, is the goal.

    Fake FedEx payment page requesting card details for a $1.20 redelivery fee.
    Fake FedEx payment page requesting card details for a $1.20 redelivery fee.

Why it still works

  • Voice Skips the Filters. Carrier SMS filtering and email gateways never see a voicemail, and the transcript hands the victim a working link anyway.
  • A Small, Plausible Ask. Most people are expecting a package at any given time, and $1.20 is too little to feel like fraud.
  • Borrowed Security Theater. Two familiar bot checks make the site feel protected. They also hide the payload: the domain in the voicemail never serves anything FedEx-branded, so a crawler or registrar checking it sees only a generic verification page.

Signals to watch for

  • A Voicemail That Names a Website. Real FedEx tracking lives on fedex.com. A voicemail pointing anywhere else to fix a delivery is the lure.
  • A Bot Check Before a Tracking Page. A Cloudflare or hCaptcha check that hands you off to an unrelated domain, such as a .shop address, is the kit, not the carrier.
  • Fake Cloudflare Artifacts. A real Cloudflare challenge carries Server: cloudflare and a cf-ray response header. One served by uvicorn or another origin, with a Ray ID that appears in no header, is fake.
  • Infrastructure Signals. WebSocket upgrades to /console/?uuid=...&EIO=4 and POSTs to /api/click_report on newly registered domains are high-confidence indicators of this kit.

How to defend against it

  • Check the package at the source. Look up the shipment yourself on fedex.com or in the FedEx app. Never visit a domain read out in a voicemail.
  • Report the number. Use your phone’s report-spam option, and in the US file a report at reportfraud.ftc.gov.
  • Treat any card entered as stolen. Call the issuer using the number on the back and ask for a replacement. An invalid-card error does not mean the details were not captured.
  • For card issuers: reissue on a reported delivery-fee scam rather than monitoring. The kit collects name, billing address, card number, expiry, and CVV, everything card-not-present fraud needs.
  • For security and brand teams: block the domains and IPs below, and watch the /24 both stages share for new hosts. Report the lure and payload domains together; removing only the one in the voicemail leaves the kit free to point a new lure at the same payload.

Why it appears here

Package-delivery scams are among the most common consumer lures, and this campaign shows the kits behind them maturing: a voice channel that bypasses message filtering, a clean redirector domain that hides the brand abuse, and a live operator channel on the payload. Nothing in the gate or the operator channel is specific to FedEx, and the lookalike domain the chain depends on is visible at registration, before the first voicemail goes out. Both domains respond to the registrar and hosting-provider abuse process described in our phishing site takedown guide.

Indicators of compromise

Domains and URLs

  • fedexwm[.]com (voicemail lure and fake Cloudflare gate)
  • dexalorin[.]shop (fake hCaptcha and FedEx payment app)
  • /api/click_report?lid=2&tid=21 (click telemetry on the gate)
  • /query/?__eat=<token> (payload entry path)
  • /console/?uuid=<uuid>&shopHost=&EIO=4&transport=websocket (operator WebSocket)

IP Addresses

  • 193.218.201[.]170 (fedexwm[.]com)
  • 193.218.201[.]135 (dexalorin[.]shop)

Lure Artifacts

  • Caller number: +1 (986) 291-9712
  • Fake tracking number: 784259631027
  • Fee amount: $1.20, split into service, storage, and tax lines

Technical Artifacts

  • Server headers: uvicorn with Via: 1.1 Caddy on the gate; openresty on the payload host.
  • Session cookie: _vt (UUID value, 10-minute lifetime) on the payload host.
  • Page metadata: <meta> tags on the payment app describing it as a login page (purpose, page-type, security-level), plus a long hex keywords value.