Cybercriminals are increasingly using phone-based social engineering to breach corporate networks, with BazaCall-style campaigns relying on fake subscription or billing emails that pressure recipients to call attacker-controlled numbers. During the call, operators posing as customer support staff persuade victims to visit malicious sites, open booby-trapped files, or install remote access tools, allowing malware such as BazaarLoader, TrickBot, and IcedID to gain a foothold while bypassing many traditional email defenses.
Threat researchers linked these call-center tactics to broader intrusion chains involving data exfiltration and ransomware, including activity associated with affiliates tied to Hive and Quantum. The operations have targeted organizations in the US, UK, Canada, and parts of Asia, with manufacturing and legal firms among the sectors observed, and have evolved into an organized underground service model that uses multilingual callers, spam lures, toll-free numbers, and ISO attachments to improve initial access success rates.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Cofense published research describing mass-distributed phone scam emails that impersonate trusted brands and pressure recipients to call attacker-controlled numbers. The report says attackers increasingly use AI to generate convincing, polymorphic lure emails at scale and highlighted tactics such as fake invoices and GitHub-linked invoice pages to add legitimacy.
Seqrite published research describing organized underground caller services used by ransomware affiliates, including actors linked to Hive and Quantum, to target organizations in sectors such as manufacturing and legal services in the US and Canada.
On its security blog, Microsoft Threat Intelligence reported on the BazaCall campaign, describing how fake call centers trick victims into installing malware that can lead to data exfiltration and ransomware deployment.
Seqrite said BazaCall-style phone-assisted malware delivery had been observed since 2021, with victims persuaded over the phone to click links, open attachments, or grant remote access as part of ransomware intrusion chains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourcecofense.com
Open sourceseqrite.com
Open sourcemicrosoft.com
Open sourcetrellix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.