BazarCall, also called BazaCall, is a callback-phishing and social-engineering malware distribution campaign. It uses fraudulent subscription-renewal or invoice lures to prompt corporate users to telephone a purported support or cancellation service. Live operators validate selected victims and direct them to counterfeit download pages, where they are persuaded to download macro-enabled Excel documents and enable macro execution. The campaign was initially associated with delivery of BazarLoader and subsequently distributed payloads including TrickBot, IcedID, and Gozi IFSB. Resulting infections have enabled remote access, lateral movement, data theft, and deployment of ransomware including Ryuk and Conti. BazarCall tradecraft has been associated with the Conti and Ryuk cybercrime ecosystem and with actors tracked as UNC2686. It primarily targeted corporate users, with substantial activity observed against organizations in the United States and additional targeting in Germany and India. Later activity linked to the broader BazarCall social-engineering model shifted toward voice-based access and extortion operations rather than necessarily delivering malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021.
Изначально исследователи связывали хакеров с атаками BazarCall, которые использовалась операторами таких вымогательских групп, как Conti и Ryuk.
The new malware was discovered being distributed by call centers in late January and is named BazarCall, or BazaCall, as the threat actors initially used it to install the BazarLoader malware.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
«Атакующий заваливает inbox жертвы спамом или отправляет убедительное уведомление ... Для отмены позвоните ... Жертва звонит по указанному номеру».
“Initial access was through phishing with a weaponized spreadsheet attachment.”
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... If the victim runs the macro code, it will download a 64-bit .dll file.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... The group used malicious spam that contains a password-protected Word document with malicious macros.
In the past several years, we have seen multiple malware samples using DNS tunneling to exfiltrate data... Anchor malware that uses DNS tunneling to communicate with C2 servers... DNS tunneling is an old technique that allows attackers to communicate with C2 servers and exfiltrate data through many firewalls.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign/toolset associated with voice-phishing style initial access activity, referenced here as used by UNC2686 from 2021.
A callback-phishing/social engineering campaign mechanism used to gain initial access by tricking targets into contacting fake IT/support personnel, historically linked here to ransomware intrusions.
BazarCall is referenced as a named attack framework/campaign used for callback-phishing style initial access and associated with operators of major ransomware groups.
Named malware/social-engineering delivery cluster referenced in the content with alternate spellings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.