Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 3 actors

BazarCall

BazarCall is a phone-based phishing and social engineering malware delivery campaign, also referred to as BazaCall, that was initially used to install BazarLoader. It was observed being distributed by live call centers beginning in late January. The campaign targets corporate users with phishing emails that typically claim a free trial or subscription is about to renew and instruct the recipient to call a phone number to cancel. During the call, operators validate a customer ID from the email to identify intended victims, then direct them to fake websites that deliver malicious Excel files in .xls or .xlsb format. Victims are instructed to open the file and enable macros, which results in malware execution. In some observed cases, callers were told to disable antivirus software.

Although initially associated with BazarLoader, BazarCall later distributed additional malware including TrickBot, IcedID, and Gozi IFSB. These infections can provide remote access, enable lateral movement and data theft, and support subsequent ransomware deployment. The content specifically notes that BazarLoader and TrickBot have been used to deploy Ryuk and Conti ransomware, while IcedID has been used to deploy Maze and Egregor. Microsoft also described BazarCall as a scam that infects victims by getting them to call a fake call center, and noted that resulting infections can lead to Anchor malware, which uses DNS tunneling for command-and-control.

BazarCall is repeatedly linked in the reporting to callback-phishing and vishing tradecraft later associated with actors in the Conti ecosystem, including UNC2686 and UNC3753/Luna Moth/Silent Ransom Group. Multiple sources state that these actors previously used BazarCall-style campaigns and that BazarCall activity was tied to Ryuk and Conti ransomware operations. The campaign is best characterized as an initial-access and malware distribution mechanism relying on convincing social engineering, fake service brands, rotating phone numbers and hosting infrastructure, and low-volume payload delivery that often resulted in low antivirus detection rates.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC2686

UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021.

via security affairssecurityaffairs.com
Silent Ransom Group

Изначально исследователи связывали хакеров с атаками BazarCall, которые использовалась операторами таких вымогательских групп, как Conti и Ryuk.

via xakepxakep.ru
WIZARD SPIDER

The new malware was discovered being distributed by call centers in late January and is named BazarCall, or BazaCall, as the threat actors initially used it to install the BazarLoader malware.

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

Like many malware campaigns, BazarCall starts with a phishing email but from there deviates to a novel distribution method - using phone call centers to distribute malicious Excel documents that install malware.

T1566.003Spearphishing via ServiceEvidence1

Instead of bundling attachments with the email, BazarCall emails prompt users to call a phone number to cancel a subscription before they are automatically charged.

Execution

2 techniques
T1059.005Visual BasicEvidence1

When the Excel macros are enabled, the BazarCall malware will be downloaded and executed on the victim's computer.

T1204.002Malicious FileEvidence1

When the user enters their customer ID number, the website will automatically prompt the browser to download an Excel document (xls or xlsb). The call center agent will then help the victim open the file and clicking on the 'Enable Content' button to enable malicious macros. | The call center agent will then help the victim open the file and clicking on the 'Enable Content' button to enable malicious macros.

Command and Control

2 techniques
T1071.004DNSEvidence1

In the past several years, we have seen multiple malware samples using DNS tunneling to exfiltrate data... Anchor malware that uses DNS tunneling to communicate with C2 servers... DNS tunneling is an old technique that allows attackers to communicate with C2 servers and exfiltrate data through many firewalls.

T1105Ingress Tool TransferEvidence1

When the Excel macros are enabled, the BazarCall malware will be downloaded and executed on the victim's computer.

Other

1 technique
T1562Impair DefensesEvidence1

In some calls conducted by Pargman, the threat actors instructed him to disable antivirus to prevent the malicious documents from being detected.

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app11 days ago
domain●●●●●●●●●●●●View more in app1 year ago
domain●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.