Dissolved Conti Affiliates Now Use Phishing Technique “Bazarcall”

Share post:

Three groups from the disbanded Conti ransomware gang are using call-back phishing technique to gain initial access to targeted networks. The advanced social engineering tactic used by the attackers is called BazaCall (BazarCall).

The three groups include Silent Ransom, Quantum and Roy / Zeon.

BazarCall is a unique phishing attack because it uses phone numbers to trick recipients into calling after being alerted to an imminent charge on their credit card for a premium subscription. This method is therefore different from the normal phishing attack where malicious links are attached to emails.

If the victim decides to call the phone number given in the email, a real person from a fraudulent call center set up by BazaCall’s operators picks and try to persuade them to give the customer service person a remote control of the desktop to help with the cancellation of the alleged subscription.

By accessing the desktop, the threat actor secretly takes steps to infiltrate the user’s network and establish persistence for follow-up activities such as data exfiltration.

“Three autonomous threat groups have since adopted and independently developed their own targeted phishing tactics derived from the call back phishing methodology. Call back phishing was the tactic that enabled a widespread shift in the approach to ransomware deployment. Attack vector is intrinsically embedded into the Conti organizational tradition,” cybersecurity firm AdvIntel said.

The sources for this piece include an article in TheHackerNews.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, March 27, 2024 – A botnet exploits old routers, a new malware loader discovered, and more warnings about downloading code from...

This episode reports on a new network of 40,000 infected small and home office routers and other devices that are part of a criminal botnet

Cyber Security Today, March 25, 2024 – A suspected China threat actor going after unpatched F5 and ScreenConnet installations

This episode reports on a new campaign stealing email passwords ,the latest data breaches

A hacker’s view of the civic infrastructure: Hashtag Trending, the Weekend Edition for March 23rd, 2024

What does the civic infrastructure look like through the eyes of a hacker? The legendary general Sun Tzu in the Art of War said that in order to defeat your enemy, you must first understand your enemy. How do you do this? He said, “to know your enemy, you must become your enemy.” If we

Cyber Security Today, Week in Review for week ending Friday, March 22, 2024

This episode features discussion on lessons learned from the ransomware attack on the British Library, advice for managing expectations of IT/security teams, why firms are leaving Google Firebase unprotecte

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways