Buying fake Justin Bieber tickets could see your phone infected with malware

app security
(Image credit: Shutterstock.com)

Scammers are increasingly leveraging call centers to carry out cyberattacks and infect their victims with malware after first roping them in by using PayPal invoices and even tickets to Justin Bieber's upcoming 2022 world tour as lures, experts have warned.

According to a new report from Proofpoint, the firm's security researchers have observed an increase in attacks that rely on victims to call scammers directly and initiate the interaction after receiving an email with their phone number. 

However, there are two types of these attacks, with one using free remote assistance software to steal money while the other, which is frequently associated with BazaCall, uses the BazaLoader malware disguised as a document to compromise a victim's computer and gain access to their online accounts.

Bieber fakes

In recent attacks, threat actors have begun emailing victims claiming to be representatives from Justin Bieber ticket sellers, computer security services, Covid-19 relief funds or online retailers with the promise of refunds for mistaken purchases, software updates or financial support. These emails contain a phone number for customer assistance but when a victim calls for help, they are instead connected with a malicious call center attendant who begins the attack.

What's clever about this new attack method is that by having victims call on their own accord, scammers are able to bypass some automated threat detection services which are only capable of flagging malicious links or attachments in emails.

Call center lures

One of Proofpoint's researchers recently identified a financially motivated telephone-oriented attack delivery (TOAD) threat that mimicked a PayPal invoice from a weapons manufacturer in the US. After calling the number on the invoice, the researcher was told to download AnyDesk and login to his bank account.

With Justin Bieber's 2022 Justice World Tour set to begin in February of next year, Proofpoint said it has seen the Canadian pop star being used quite frequently as a lure associated with BazaCall threats. 

After calling the number on a fake ticket invoice, the firm's researcher was put on hold with Bieber's music playing in the background. Once the scammer got on the line, they claimed that someone had erroneously placed an order on the researcher's credit card and by going to ziddat[.]com/code.exe, a refund could be issued. After visiting the site, the BazaLoader malware was successfully downloaded on the researcher's virtual machine.

What makes call center-based email threats so dangerous is that the scammers behind them don't specifically target victims based on demographics, jobs or location but likely procure their contact information from legitimate data brokerages or other telemarketer resources. Proofpoint is aware of victims losing nearly $50k in one attack with the threat actor pretending to be a representative from NortonLifeLock.

In addition to PayPal and Justin Bieber, call center-based email threat campaigns often impersonate a number of popular brands including Norton, MacAfee, eBay, GeekSquad, Santander Bank, Amazon, Symantec and others. 

To prevent falling victim to these sorts of attacks, users should remain vigilant when checking their email and avoid calling the phone numbers contained in any suspicious emails, especially for items they didn't purchase.

Protect your identity and data online with the best antivirus software, the best malware removal software and the best identity theft protection tools

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Robotic hand clicking on captcha 'I am not a robot'.
Fake CAPTCHAs are being used to spread malware - and we only have ourselves to blame
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models