Home » Callback phishing

Callback phishing

CallBack phishing is a spearphishing method used by Ransomware threat actors as an initial access method.

In practice, it involves ursuper the identity of legitimate platforms or companies by sending emails claiming that the victim has been or will be charged for a service. Then, she urges victims to call a listed phone number for further clarification.

By calling this number, the victim is directed to a call center service created for the occasion, by the authors of the threat. Over the phone, a “customer service representative” then seeks to gain remote access and distribute malware and/or steal data from the victim’s network.

As you can see, callback phishing is a method that uses relatively advanced social engineering tricks, interfering with those of tech support scams to gain remote access.

This method, also known as BazarCall, first appeared at the beginning of 2021. It was then used by Ransomware groups such as Ryuk and later Conti followed by Luna Moth (aka Silent Ransom aka TG2729), Quantum and Roy/Zeon (aka Royal).

As explained by our CTI analysts in their report on the state of the ransomware threat in the second quarter of 2022, the use of callback phishing among ransomware threat actors continues to grow. In the second quarter of 2022, it increased by 625% compared to the first quarter of 2021.

They also believe that more personalized versions of callback phishing campaigns could emerge in the future and hinder tracking and detection efforts. Especially since the phishing messages used do not include malicious components per se. Their use by cybercrime groups could therefore increase in 2023.

Read more about this Sekoia.io report focused on ransomware threat news, click on this link: https://blog.sekoia.io/sekoia-io-ransomware-threat-landscape-second-half-2022/.

Sekoia.io is a European cybersecurity software company. Through cyber threat intelligence and the automation of defense capabilities, we give systems protection teams the advantage of detecting IT threats before impact. Our products include a threat intelligence tool, an XDR platform on which you can interconnect without constraint, the security solutions necessary to protect your infrastructure but also automate your actions thanks to SOAR.

Others Terms

SOC(Security Operations Center)

Security Operations Center (SOC) is an organizational structure dedicated to the implementation of all the security operations of an organization against cyberattacks. These actions include the supervision and protection of an organization’s information system (workstations, networks, website, applications, databases, etc.)

XDR(eXtended Detection & Response)

XDR (eXtended Detection & Response) designates a holistic approach to cybersecurity operational. It stands out for its ability to consolidate and automate on a unified SaaS platform all data, analyzes and responses to cyber threats, regardless of their origin, supplier or specialization.

Échangez avec l’équipe

Vous souhaitez en savoir plus sur nos solutions de protection ?
Vous voulez découvrir nos produits de XDR et de CTI ?
Vous avez un projet de cybersécurité dans votre organisation ?
Prenez rendez-vous et rencontrons-nous !

Chat with our team !

Would you like to know more about our solutions ?
Do you want to discover our XDR and CTI products ?
Do you have a cyber security project in your organization ?
Make an appointment and meet us !