Criminals are now posing as security companies to trick you into installing malware

Cartoon Phishing
(Image credit: Shutterstock / DRogatnev)

Cybercriminals are impersonating cybersecurity companies to try and lure victims into downloading compromising programs. 

An investigation by Crowdstrike, one of the cybersecurity companies impersonated in the campaign, uncovered a “callback phishing” campaign in which threat actors are reaching out to various companies via email, telling them their endpoints are compromised, and urging them to call the company back for further instructions on how to eliminate the threat.

The email also carries the phone number that the victims should call, and as you might imagine, it doesn’t belong to the actual company, but rather to the attackers.

Legitimate software and nefarious goals

If the victim falls for the scam and actually calls the number in the email address, the person on the other end of the line will try and persuade them into downloading “common legitimate remote administration tool (RATs),” which would give them access to the target network. Furthermore, they’d try and get the victim to install off-the-shelf penetration testing tools, such as Cobalt Strike, to allow for lateral movement. 

Following the successful breach and lateral movement, the attackers will look to deploy ransomware, although Crowdstrike could not say exactly which ransomware variant they use. 

One of the reasons why such a campaign could be relatively successful is the fact that the emails carry no links, or attachments. As such, it is possible for email security solutions, as well as antivirus programs, not to detect these emails as malicious, and release them to the target’s inbox.

What’s more, giving cyberattackers your phone number also opens up an additional avenue for attacks.

It’s not exactly a new strategy. Cybercriminals have been using this approach for months now, as email security systems grew more sophisticated and better at spotting malicious actors. 

Around Black Friday 2021, scammers were also found to be impersonating big brands such as Amazon, Target, and Walmart, attempting to get victims to call them.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Magnifying glass enlarging the word 'malware' in computer machine code
Microsoft Teams and AnyDesk abused to deploy dangerous malware, so be on your guard
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Latest in Security
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Latest in News
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Project Moohan prototype at Samsung Galaxy Unpacked, an XR goggles headset on display in a show area
Samsung's Android XR headset could avoid the Apple Vision Pro's biggest mistake, according to this leak