Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BazarCall

Also known as: BazzarCall, BazaCall

Description

BazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique reminiscent of vishing and tech support scams where potential victims are being cold called by the attacker, except in BazarCall’s case, targeted users must dial the number. And when they do, the users are connected with actual humans on the other end of the line, who then provide step-by-step instructions for installing malware into their devices.

AI Analysis

· 1 week ago

Executive Summary

BazarCall is a threat actor that leverages social engineering tactics, particularly phishing via phone calls, to manipulate victims into installing malware on their devices. This group stands out for its use of human operators to guide victims through the infection process, making their attacks more personal and effective.

Goals & Targeting

BazarCall's primary objective appears to be financial gain and data theft. They target individuals across various sectors by exploiting human vulnerabilities, making their attack vectors difficult to detect compared to traditional malware campaigns. Their targeting strategy underscores a shift towards more interactive and personalized attack methods in cybercrime.

Enhanced Description

BazarCall employs a unique approach by integrating phishing with voice-based social engineering. They send emails containing phone numbers, persuading recipients to call these numbers under the guise of legitimate communication. Upon calling, victims are connected to human operators who provide detailed instructions for downloading malware, often mimicking tech support or other trustworthy entities. This method avoids traditional email-based payloads and instead relies on direct interaction to achieve infection. The group's operations raise concerns about the evolving tactics in cyberattacks, where trust is exploited through personal engagement.

Key Capabilities

  • Social-engineering via phone calls
  • Guiding victims through malware installation
  • Evading detection by avoiding traditional email payloads

MITRE ATT&CK Tactics

Initial Access

ATT&CK Techniques

T1566.004

Software / Tooling

RemoteAccessTool (RAT)

Campaigns & Victims

BazarCall has been observed targeting various industries, including finance and healthcare. Their operations often involve extensive research to personalise their approach. Notable campaigns include those that use fake tech support calls, leveraging trust to deploy malicious payloads. The group's operational tempo is steady, with periodic campaign launches.

IOC Patterns

  • Reception of unexpected phone calls prompting immediate action
  • Calls appearing from legitimate-looking numbers
  • Installation of unknown files after a call

Recommended Actions

  • Educate users on phishing over voice and the dangers of calling suspicious numbers
  • Implement caller ID verification technologies
  • Monitor IT systems for signs of remote access tool activity
  • Conduct regular security awareness training

Suggested Tags

APT
Social Engineering
Phishing
Banking Threat
E-Security

Confidence Assessment

Low confidence due to limited available information on BazarCall. Unknown aspects include their exact motivations, targeting criteria beyond known campaigns, and full list of TTPs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
Social Engineering
Banking Threat
E-Security

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.