Phonescams: Casting a Wide Net in an Orchard of Low-Hanging Fruit
Threat actors are distributing mass phone scam phishing campaigns that impersonate well-known brands. The campaigns leverage AI to generate polymorphic email variations that bypass secure email gateways. The lures direct recipients to call fraudulent VoIP numbers under the pretense of resolving unauthorized purchases or password resets, exploiting the recipient's fear of financial or account loss.
- urlhxxps://github[.]com/ericarowe/miniature-robotGitHub repository abused to host a fake Geek Squad invoice as part of a phone scam lure.
- urlhxxps://github[.]com/ericarowe/miniature-robot/commit/08941cd4d0f51eeab33bdc13d8f838530ded8014Specific GitHub commit URL used to direct victims to the fake invoice page.
- urlhxxps://www[.]amazon[.]com/a/c/r/Legitimate Amazon domain path used in a password recovery phishing lure.
Detection / Hunteropenrouter
What Happened
Scammers are sending large numbers of fake emails that look like they come from trusted companies like Amazon, Microsoft, and Apple. These emails claim there is a problem, like an unauthorized purchase or a password reset, and urge the recipient to call a phone number for help. The scammers use artificial intelligence to quickly create many variations of these emails, making them hard for standard email filters to catch. Some scams even use legitimate services like GitHub to host fake documents. Anyone who receives emails should be cautious of messages that create a sense of urgency and demand a phone call. Verify any claims directly through the company's official website or app rather than calling numbers provided in unsolicited emails.
Key Takeaways
- Threat actors are mass-distributing phone scam emails impersonating major brands like Microsoft, Amazon, Target, and PayPal.
- AI is used to generate thousands of convincing, polymorphic email variations rapidly, lowering the barrier to entry for scammers.
- Scams pressure recipients to call VoIP numbers by creating a false sense of urgency regarding unauthorized purchases or password resets.
- Some lures abuse legitimate platforms like GitHub to host fake invoice links, adding a layer of authenticity to the scam.
- Email spoofing techniques make the lures appear to originate from legitimate sender addresses.
Affected Systems
- Email users
- Consumers of Amazon, Microsoft, Apple, PayPal, Target, Canva, Temu, GitHub, and Norton
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Threat actors distribute polymorphic phishing emails impersonating major brands using spoofed sender addresses.
- Execution: The email lures claim an unauthorized purchase, password reset, or subscription, creating a false sense of urgency.
- C2: The lure directs the recipient to call a fraudulent VoIP phone number for remediation.
- Exfiltration: Once on the phone, scammers manipulate the victim into providing sensitive information or granting remote access to financial accounts.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules are provided in the article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The attack primarily relies on social engineering via email and phone calls. Endpoint telemetry would only capture activity if the victim interacts with a malicious link or attachment, which is not the primary vector here. |
| Network Visibility | Medium | Network monitoring could detect access to the GitHub repository URL used for the fake invoice. However, the primary communication channel is a phone call to a VoIP number, which is outside standard network security monitoring. |
| Detection Difficulty | Moderate | The use of AI to generate polymorphic email variations and spoofed legitimate sender addresses makes email-based detection challenging. Detection relies on identifying the fraudulent phone numbers and the sense of urgency in the email body. |
Required Log Sources
- Email gateway logs
- Web proxy logs
- DNS logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for emails containing urgent language about unauthorized purchases or password resets that also include a phone number and discourage replying to the email. | Email gateway logs, email body content analysis | Initial Access | Medium - Legitimate customer service emails may contain phone numbers and urgent language. |
| Hunt for access to the specific GitHub repository or commit URL used to host the fake invoice. | Web proxy logs, DNS logs | Execution | Low - The specific repository and commit are directly tied to the scam. |
Control Gaps
- Standard email security gateways may fail to detect polymorphic, AI-generated phishing emails.
- Security monitoring does not typically cover voice communications (VoIP calls) initiated by phishing lures.
Key Behavioral Indicators
- Emails impersonating major brands that include a phone number for support.
- Emails that discourage replying to the sender and push communication to a phone call.
- Spoofed sender addresses that appear to come from legitimate domains but are part of a scam campaign.
- Use of free email services (e.g., Gmail) to impersonate official organizations like the FTC.
False Positive Assessment
Medium - Legitimate customer service emails from major brands may contain phone numbers and urgent language regarding account access or purchases.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified fraudulent phone numbers and sender addresses on your email gateway if supported.
- Consider blocking or alerting on access to the identified GitHub repository URL used in the scam.
Infrastructure Hardening
- Evaluate whether your email security solution can detect polymorphic, AI-generated phishing emails and consider enhancing email filtering rules to flag messages with urgent purchase or password reset language that include phone numbers.
- Implement DMARC, DKIM, and SPF policies if not already in place to help prevent email spoofing.
User Protection
- Consider rolling out awareness training that specifically addresses phone scam lures, emphasizing the tactic of creating a false sense of urgency and pushing communication to a phone call.
- Advise users to verify any unauthorized purchase or password reset claims directly through the official website or app of the impersonated brand, not through contact information provided in an email.
Security Awareness
- Consider incorporating examples of these brand impersonation phone scams into existing security awareness programs.
- Reinforce the message that legitimate organizations will not discourage replying to an email or demand immediate action via a phone call.
MITRE ATT&CK Mapping
Initial Access
Additional IOCs
- Urls:
hxxps://www[.]amazon[.]com/a/c/r/- Legitimate Amazon domain path used in a password recovery phishing lure.
- Other:
818 418-6367- Fraudulent VoIP helpline number used in a Target purchase scam.+1 (864) 285-8021- Fraudulent VoIP helpline number used in a Microsoft/Azure schedule scam.(815)-296-3385- Fraudulent VoIP helpline number used in an Amazon password recovery scam.1-888-877-4206- Fraudulent VoIP helpline number used in an Apple/PayPal app-specific password scam.+61 (04) 8998 0525- Fraudulent VoIP helpline number used in a Canva school invitation scam.805 302-4074- Fraudulent VoIP helpline number used in an FTC Financial Protection Review scam.802 303 3320- Fraudulent VoIP helpline number used in a Temu password reset scam.+1 802 300 0244- Fraudulent VoIP helpline number used in a Geek Squad billing scam.[email protected]- Spoofed sender address used in a Target purchase scam.[email protected]- Spoofed sender address used in a Microsoft/Azure schedule scam.[email protected]- Spoofed sender address used in an Amazon password recovery scam.[email protected]- Spoofed sender address used in an Apple/PayPal scam.[email protected]- Spoofed sender address used in a Canva school invitation scam.[email protected]- Free email address used as sender in an FTC Financial Protection Review scam.[email protected]- Spoofed sender address used in a Temu password reset scam.[email protected]- Spoofed sender address used in a GitHub notification/Gek Squad billing scam.[email protected]- Email address mentioned in the body of a Microsoft/Azure schedule scam.