BazarCall is a unique vishing operation using phone numbers in emails, with live operators guiding victims to deploy BazarLoader payloads.
Analyst brief
BazarCall is a unique social engineering operation that distributes phone numbers via email to trick victims into making calls, avoiding the use of malicious links or attachments entirely. They primarily target corporate users, connecting them with live call operators who provide step-by-step instructions to install malware on the victim's device. The main TTP involves vishing and the use of remote assistance tools to deploy initial loaders like BazarLoader. Defenders should focus on user awareness training regarding these phone-guided emails and consider blocking known callback numbers, especially in enterprise environments.
BazarCall
BazzarCallBazaCall
unknown
BazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique reminiscent of vishing and tech support scams where potential victims are being cold called by the attacker, except in BazarCall’s case, targeted users must dial the number. And when they do, the users are connected with actual humans on the other end of the line, who then provide step-by-step instructions for installing malware into their devices.
What does the BazarCall group typically use in email messages to trick victims?+
BazarCall uniquely avoids the use of malicious links or attachments in email messages; instead, they use phone numbers that recipients are misled into calling.
What happens when a victim calls the number provided by BazarCall?+
When a victim calls, they are connected with actual human operators on the other end of the line who then provide step-by-step instructions for installing malware on their device.