What is callback phishing?
Callback phishing is a social engineering attack in which a lure, usually an email, prompts the victim to call a phone number instead of clicking a link or opening an attachment. When the victim calls, an attacker posing as a support agent for a trusted brand uses a scripted conversation to extract credentials or one-time passcodes, obtain payment, or talk the victim into installing remote access software. Because the email contains no malicious link or attachment, only a phone number, it slips past content-based email filters. That's precisely what makes the technique effective. Callback phishing is also known as Telephone-Oriented Attack Delivery (TOAD) and, in its original form, as BazarCall. What distinguishes callback phishing from ordinary phishing is the reversal of initiative: the victim makes the call, so the interaction feels voluntary and their guard is down. Ransomware crews adopted it as a reliable initial-access technique, and it now spans enterprise attacks and consumer fraud alike. This page explains how it works, where it came from, the brands and tools attackers abuse, how it differs from vishing and smishing, and how organizations can detect and defend against it.
Key takeaways
- Callback phishing replaces the click with a call. The lure email carries only a phone number, so it evades link- and attachment-based email defenses and lands in the inbox.
- The victim initiates contact, which lowers suspicion. Unlike vishing, where the attacker calls the victim, here the victim dials the attacker, making the conversation feel trustworthy and voluntary.
- It's also called TOAD and BazarCall. Telephone-Oriented Attack Delivery is the technical name; BazarCall was the 2020–2021 campaign that pioneered it as a ransomware initial-access vector.
- Ransomware groups rely on it. Ryuk, Conti, and splinter groups such as Luna Moth (Silent Ransom Group), Quantum, and Royal have used callback phishing for initial access, malware delivery, and extortion.
- Human awareness is the primary defense. Because there's nothing malicious for filters to catch at delivery, employee recognition, verification habits, and remote-access policy are the front line.
How callback phishing works
A callback phishing attack unfolds across two stages, deliberately splitting the lure (email) from the payload (the phone call) so that no single channel carries an obvious red flag.
Stage 1: The lure
The victim receives an email that looks like a routine billing or account notice: a subscription about to auto-renew, an invoice for a purchase they don't recognize, or a fraud alert. The message impersonates a trusted brand and creates mild urgency, but it contains no malicious link and no malware, just a phone number to call "for help" or "to cancel." Some campaigns attach a benign-looking PDF (frequently generated through abused document platforms) that carries the number, which is why these attachments routinely pass antivirus and sandbox checks. The lure can also arrive by SMS, or the number can be planted in forums, fake listings, and search results so the victim believes they found it themselves.
Stage 2: The call
When the victim dials, a live operator answers using a script matching the impersonated brand, often from a purpose-built fake call center. This is where the real attack happens. The operator personalizes the pitch, overcomes objections, and walks the victim through the steps the attacker needs: reading out a one-time passcode, confirming credentials or payment details, or, most damaging in enterprise cases, installing a remote access or remote monitoring and management (RMM) tool such as AnyDesk, GoTo, or SimpleHelp. Once connected, the attacker can take control of the machine, blank the screen to hide activity, steal data, and drop follow-on malware. Attackers typically use Voice over IP (VoIP) numbers, which are cheap, anonymous, and hard to trace, and reuse them for only a day or two before rotating.
The origins of callback phishing: BazarCall and ransomware
Callback phishing was pioneered by the BazarCall campaign, first observed in 2020 and widespread by early 2021. Operators sent subscription-renewal emails for fake antivirus or software products and directed victims to call a support number to cancel. The phone operator then walked the victim through downloading BazarLoader (later BazarBackdoor), a remote access trojan that served as the launchpad for ransomware.
BazarCall's success created a template that multiple ransomware operations adopted. The Ryuk group used callback phishing for initial access, Conti inherited and industrialized the playbook, and after Conti dissolved in 2022 the technique passed to splinter and successor groups, including Luna Moth (also tracked as Silent Ransom Group), Quantum, and Royal (Zeon), with newer operations such as 3AM continuing to use it. Royal operators in particular were noted for sending emails that contained only a phone number in place of a traditional payload. According to Sekoia's own threat intelligence research on the ransomware landscape, use of callback phishing among ransomware actors grew by roughly 625 percent in the second quarter of 2022 compared with the first quarter of 2021, and the technique has continued to professionalize since.
Why callback phishing evades traditional defenses
Callback phishing is effective for structural reasons, which is why adding more email filtering rarely solves the problem:
- No malicious artifact at delivery. The lure email has no link and no attachment to scan, so signature- and reputation-based email security has nothing to flag. The payload lives in a phone conversation that no email tool can see.
- Channel switching creates a blind spot. The attack moves from email to voice, and most security stacks aren't built to correlate signals across both channels, so the most dangerous phase happens where monitoring is weakest.
- Victim-initiated contact disarms suspicion. Because the victim places the call, they already believe they're talking to a legitimate organization, so the usual wariness about unsolicited calls doesn't apply.
- Live social engineering beats static controls. A real operator can improvise, apply urgency and authority, and adapt on the fly (switching the requested tool when a victim mentions a Mac, for example), which no scripted defense anticipates.
- AI voice cloning raises the stakes. Attackers increasingly use AI-generated voices to sound more convincing and even impersonate specific individuals, making the voice channel harder to trust.
Callback phishing vs vishing vs smishing
These phone- and message-based social engineering techniques are related and often confused, but the direction of contact and the channel differ in ways that matter for defense.
The key distinction is who dials whom. In vishing the attacker calls in, so the target is on guard against an unsolicited caller. In callback phishing the victim calls out, which flips the psychology: the target believes they initiated a legitimate support interaction, so they're far more likely to comply. Callback phishing often uses email or SMS as the lure and voice as the payload, so it overlaps with both vishing and smishing without being identical to either.
Common lures, impersonated brands, and real examples
Callback phishing lures cluster around believable billing and account events. Threat intelligence on recent campaigns shows attackers most often impersonate well-known consumer and enterprise brands, among them Microsoft, Norton LifeLock, PayPal, DocuSign, Best Buy's Geek Squad, and accounting software such as QuickBooks. The recurring themes are subscription auto-renewals, unexpected invoices, and antivirus or fraud alerts, all chosen because a renewal or charge notice doesn't immediately seem out of place in a busy inbox.
A widely cited example illustrates the pattern clearly: a security executive received an email impersonating QuickBooks with an attached file and a phone number; none of 63 antivirus engines flagged the attachment, and when he called, the operator tried to get him to install remote access software, immediately switching to a different tool when he mentioned he used a Mac. In enterprise attacks, the same playbook escalates to data theft and ransomware; in consumer fraud, it typically ends in drained accounts, fraudulent refunds, or gift-card payments.
How to prevent and detect callback phishing
Because there's no malicious artifact to block at delivery, defense depends on people, process, and post-compromise detection rather than email filtering alone:
- Train for this specific technique. Generic phishing training doesn't cover TOAD. Teach employees that a billing email with only a phone number is a known attack pattern, and run callback phishing simulations, which frameworks such as NIST SP 800-172 recommend as part of security awareness programs.
- Verify numbers and requests independently. Never call a number from an unexpected email; look up the organization's real support line from its official site. Treat search-result phone numbers with suspicion, since scam numbers are deliberately planted to rank.
- Set a clear remote-access policy. Make it a rule that legitimate IT will never ask an employee to install a remote access tool via a call the employee placed. This single policy defeats the most damaging enterprise outcome.
- Monitor for unexpected RMM tool installations. Legitimate tools such as AnyDesk, GoTo, and SimpleHelp are routinely abused; their appearance in an unusual context is a high-value detection signal for a SOC.
- Verify identity out of band and protect OTPs. Confirm any urgent caller through a separate, trusted channel before acting, and never read out one-time passcodes. AI voice cloning makes out-of-band verification essential.
For consumers, the guidance is simpler: don't call numbers from unsolicited billing emails, be wary of urgency and threats, and if caught, contact the real company immediately, change passwords, and monitor accounts.
Expert insight: Detection has to move past the inbox
Callback phishing is designed to be undetectable by the tools most organizations rely on at delivery. There's no URL to blocklist and no attachment to detonate, so the lure frequently arrives clean. Meaningful detection opportunities aren't at the email gateway; they're later, on the endpoint and in the network, when the attacker acts on the access the victim just handed over.
This is where Sekoia's CTI-led approach is relevant. Sekoia tracks the ransomware groups that operate callback phishing campaigns, and its in-house Threat Detection & Research (TDR) team published early analysis of the technique's growth among ransomware actors. That intelligence feeds directly into the platform. Rather than trying to catch a lure that carries no payload, Sekoia's AI SOC platform focuses on the observable consequences: the sudden installation or execution of a remote access or RMM tool, anomalous remote-session behavior, and the follow-on malware and lateral movement that a successful call enables. Detection content is mapped to MITRE ATT&CK and enriched with native threat intelligence, so an unexpected AnyDesk or SimpleHelp execution surfaces as an alert with context rather than unexplained noise. Unifying endpoint, network, and identity telemetry in one platform closes the email-to-voice-to-endpoint blind spot that lets callback phishing succeed.
Treat callback phishing as a two-front problem. Reduce the human failure rate at the point of the call through training and clear policy, and make sure your detection strategy assumes some calls will succeed so the post-compromise activity is caught quickly. As a European vendor with a data-sovereignty posture and native CTI, Sekoia is built for that second front.