Back to blog

“Callback Phishing”: A New Cyber Threat

B
BlueSecure
Équipe BlueSecure
October 16, 20233 min read
“Callback Phishing”: A New Cyber Threat

Although phishing attacks are primarily carried out via e-mail, we have observed a significant increase in hybrid phishing attacks in recent months, particularly “Callback Phishing.”

What Is “Callback Phishing”?

Traditional e-mail phishing is commonly used to steal credentials or distribute malware. However, many companies have strengthened their e-mail security, often identifying and blocking such malicious content. At the same time, some attackers are turning to vishing, a phishing variant in which the victim is approached by phone using social engineering tactics.

“Callback Phishing” combines these two approaches. First, an e-mail is sent to an individual or business, reporting a potential issue, such as an unpaid bill or a fake security alert. Rather than including a link in the e-mail, a phone number is provided. The recipient is then encouraged to call that number.

The number leads directly to the cybercriminal who, through social engineering, attempts to obtain sensitive information from the individual, convince them to download malicious software, or establish a remote connection.

The subtlety of “Callback Phishing” is that it often bypasses traditional e-mail security systems. Indeed, the only potentially malicious element in the e-mail is a phone number, which is generally difficult to identify as suspicious.

The Rise of “Callback Phishing”

The Ryuk ransomware group began using this technique in 2019. Although Ryuk ceased operations, the group evolved into Conti, which has also since disappeared. However, groups such as Royal (which attacked the Lille city hall in France) have incorporated “Callback Phishing” into their arsenal to compromise their targets’ systems. They often impersonate legitimate companies in their initial e-mails in order to deceive their victims. For example, by sending an e-mail in Microsoft’s name with an invoice for Windows licenses. To dispute the invoice, the only option is to call the listed number. The cyberattacker on the other end of the line will then convince their target to install a utility to verify the authenticity of the licenses. In reality, this software is a tool for remotely taking control of the workstation, or even ransomware itself.

Other groups also exploit “Callback Phishing” by posing as cybersecurity experts and warning their victims of an alleged imminent threat.

Hybrid attacks such as “Callback Phishing” have seen tremendous growth this year and, given how difficult they are to intercept, this growth is expected to continue.

Microsoft bill phishing call back

Protecting Yourself Against “Callback Phishing”

A defense strategy against “Callback Phishing” requires a multi-layered approach.

E-mail filtering solutions, such as anti-spam tools, are of course now an essential part of security protection. Some even offer advanced features such as content and external link analysis. However, they are not sufficient, as certain targeted e-mails, such as spear phishing attacks, can slip through the net.

In the event of credential leakage, authentication must also be strengthened by making multi-factor authentication mandatory on sensitive systems.

However, the best defense remains employee training and awareness. It is crucial to familiarize employees with “Callback Phishing” tactics, prepare them to respond appropriately to suspicious e-mails, and train them to recognize the key indicators of this threat.

Our BlueSecure awareness and training platform enables your employees to acquire all the essential skills needed to effectively detect and respond to these e-mails.

Thanks to our awareness and training program, your organization will be ready to face any potential phishing-related threat, regardless of the channel used (e-mail, SMS, QR codes, USB drives, phone calls, etc.).

Contact us now to learn more!

CONTACT US

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article