Cyber Security News

Callback Phishing Attacks Using Google Groups To Steal Login Details

Phishing attacks are deceptive schemes where attackers impersonate reputable entities to trick individuals into revealing “sensitive information.”

These attacks often occur via email using urgent language to prompt victims to click on “malicious links” or “download harmful attachments.”

Trustwave cybersecurity analysts recently warned of Callback Phishing attacks that target Google groups to steal login details.

Callback Phishing Attacks

Trustwave SpiderLabs documented a significant surge of “140%” in “callback phishing attacks” (aka “Telephone-Oriented Attack Delivery” or “TOAD”) between July and September. 

They discovered that the attacks evolved from their earlier discovery of a “fake order spam scheme” via Google Groups. 

Join ANY.RUN's FREE webinar on How to Improve Threat Investigations on Oct 23 - Register Here 

This sophisticated “hybrid cyberattack” combines “traditional email phishing” with “social engineering” via “phone calls,” where threat actors employ various “TTPs.” 

The attack begins with “phishing emails containing text obfuscation” (‘using base64 encoding’ and ‘invisible characters’), “image-based spam” (‘.gif files’), or “document-based lures” (‘PDF,’ ‘.txt,’ ‘.doc’ formats) impersonating legitimate brands. 

Callback phishing attack flow (Source – Trustwave)

These emails prompt victims to call provided phone numbers about “fake invoices” or “account terminations” and not only that even they often evade “text-based spam filters.” 

The attack then decides into three primary vectors:- 

  • Vishing (voice phishing) for stealing PII and banking credentials.
  • Malware deployment (like “BazarCall” distributing “BazarLoader malware”).
  • Remote access exploitation (as seen in “Luna Moth campaigns”).
Calendly scheduler (Source – Trustwave)

The scheme’s effectiveness stems from its “dual-channel approach,” which helps in incorporating “real-time social manipulation” via “phone calls,” “delayed detection due to minimal digital footprints,” and “integration with legitimate services like Calendly for scheduling fraudulent support calls.” 

These things make it particularly challenging for traditional security measures to detect and prevent.

Callback sent using Paypal (Source – Trustwave)
Callback phishing sent using Xero (Source – Trustwave)
Bogus QuickBooks invoice (Source – Trustwave)


Callback phishing sent using Honeybook (Source – Trustwave)

Financial platforms are experiencing sophisticated cybersecurity breaches where attackers exploit legitimate services like “PayPal,” “Xero,” “QuickBooks,” and “HoneyBook” via “callback phishing.” 

These attacks leverage authentic email authentication protocols like “DKIM” (‘DomainKeys Identified Mail’) signatures and “platform-specific header stamps,” to evade security measures. 

The attackers create fraudulent payment requests and invoices by sending them first to “dummy email addresses” before “forwarding them to actual victims,” thereby evading “email authentication checks.” 

The malicious emails contain legitimate “From” addresses, “authentic platform links,” and “genuine website redirects,” which makes them particularly deceptive. 

However, the distinguishing red flags include “suspicious payment notes,” “mismatched “To” addresses using newly registered domains,” and “fraudulent customer service phone numbers.” 

This attack vector is particularly effective as it combines “social engineering” with “technical legitimacy” under which the emails pass through “security filters” since they originate from trusted financial platforms, yet they incorporate urgency triggers like “overdue payments” or “account anomalies” to manipulate victims into calling fake support numbers. 

The process illustrates a sophisticated evolution of “TOAD” where attackers exploit the inherent trust in established financial platforms’ infrastructure while maintaining the human manipulation aspect of traditional phishing schemes.

Recommendations

Here below we have mentioned all the recommendations:-

  • Be cautious of uninvited emails.
  • Use official contacts, not email-provided numbers.
  • Don’t share personal info on calls.
  • Monitor bank accounts and report irregularities.
  • Stay updated on phishing and also train employees.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago