BazarCall, also written BazaCall, is a callback-phishing and social-engineering malware delivery operation used to gain initial access to enterprise environments. It is best known for sending subscription or invoice-themed emails that pressure recipients to call a phone number, after which live operators guide selected victims to a spoofed website and instruct them to download and open a malicious spreadsheet, typically enabling macros to execute the next stage. The activity was initially associated with delivery of BazarLoader and has also been reported distributing other malware families including TrickBot, IcedID, and Gozi IFSB, making it functionally similar to a distribution-as-a-service channel for follow-on intrusion activity.
The operation relies heavily on human interaction rather than exploit-driven compromise. Operators validate victims, direct them through the download process, and in some cases instruct them to weaken defenses to ensure execution. Successful infections provide an initial foothold that can support broader post-compromise activity, including additional payload delivery, remote access, lateral movement, data theft, and eventual ransomware deployment by downstream actors. BazarLoader infections delivered through this ecosystem have been linked to Ryuk and Conti intrusion chains, and the broader tradecraft has been associated with clusters overlapping the Conti ecosystem, including actors later tracked as UNC2686 and UNC3753 in related callback-phishing operations.
BazarCall primarily targets Windows enterprise users through phishing emails and voice-based social engineering. It has been observed extensively against organizations in the United States and also against victims in other countries. Over time, the callback-phishing model associated with BazarCall influenced later extortion-focused campaigns in which threat actors shifted from malware delivery toward remote-access social engineering, but BazarCall itself remains most accurately characterized as a phone-assisted malware delivery and initial-access mechanism centered on delivering loader-stage infections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021.
Изначально исследователи связывали хакеров с атаками BazarCall, которые использовалась операторами таких вымогательских групп, как Conti и Ryuk.
The new malware was discovered being distributed by call centers in late January and is named BazarCall, or BazaCall, as the threat actors initially used it to install the BazarLoader malware.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... If the victim runs the macro code, it will download a 64-bit .dll file.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... The group used malicious spam that contains a password-protected Word document with malicious macros.
In the past several years, we have seen multiple malware samples using DNS tunneling to exfiltrate data... Anchor malware that uses DNS tunneling to communicate with C2 servers... DNS tunneling is an old technique that allows attackers to communicate with C2 servers and exfiltrate data through many firewalls.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign/toolset associated with voice-phishing style initial access activity, referenced here as used by UNC2686 from 2021.
A callback-phishing/social engineering campaign mechanism used to gain initial access by tricking targets into contacting fake IT/support personnel, historically linked here to ransomware intrusions.
BazarCall is referenced as a named attack framework/campaign used for callback-phishing style initial access and associated with operators of major ransomware groups.
Named malware/social-engineering delivery cluster referenced in the content with alternate spellings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.