Callback phishing attacks have evolved their social engineering methods, using old fake subscriptions and pretending to help victims deal with an attack.
See also: Microsoft Defender for Office 365: Teams users will be able to report phishing messages

Successful attacks infect victims with a malware loader, which drops additional payloads such as remote access trojans , spyware , and ransomware.
Callback phishing attacks, i.e. those that use callbacks, pretend to be expensive subscription services, which try to confuse the recipient, who has never subscribed to these services.
The email includes a phone number that the recipient can call to learn more about this “subscription” and cancel it. However, this leads to a social engineering attack that deploys malware on victims’ devices and potentially ransomware attacks.
According to a new report by Trellix, the most recent campaigns target users in the United States, Canada, the United Kingdom, India, China, and Japan.
Callback phishing attacks first appeared in March 2021 under the name “BazarCall,” where malicious actors began sending emails telling users they were subscribers to streaming services, software products, or medical services companies, giving a phone number to call if they wanted to cancel the subscription.
When a recipient called the number, the malicious actors told them to follow a series of steps that ultimately led to the download of a malicious Excel file that would install the BazarLoader malware .
See also: Germany arrests hacker for stealing 4 million euros through phishing attacks
BazarLoader would provide remote access to an infected device, providing initial access to corporate networks and eventually leading to Ryuk or Conti.

Over time, these attacks have emerged as a significant threat, as they are now used by numerous hacking groups, including Silent Ransom Group, Quantum , and Royal ransomware.
The process has changed in the most recent Callback phishing campaigns, although the bait in the phishing email remains the same, an invoice for a payment made to Geek Squad, Norton, McAfee, PayPal or Microsoft.
Once the recipient calls the scammer at the provided number, they are asked to provide billing information for “verification.” The scammer then states that there are no matching records in the system and that the email the victim received was spam.
The supposed customer service representative then warns the victim that the spam email may have resulted in a malware infection on their computer, and offers to connect them with a specialist to help them.
After a while, a different scammer calls the victim to help with the infection and directs them to a website where they download malware disguised as antivirus software.
See also: New phishing campaign targets military contractors
Another variation used in PayPal-themed phishing attacks is to ask the victim if they use PayPal and then ask to check their email for a breach, claiming that their account was accessed from eight devices in various locations around the world.
The result of all these campaigns is to convince the victim to download malware, which could be BazarLoader, remote access trojans, Cobalt Strike, or some other remote access software, depending on the threat agent.
