Microsoft, PayPal, DocuSign, and Geek Squad faked in callback phishing scams
ID: 76bac4b5-e141-5788-afe7-48abdf9f8f61
STIX ID: report--76bac4b5-e141-5788-afe7-48abdf9f8f61
Feed Name: Malwarebytes Blog
Researchers at Cisco Talos observed a May–June phishing campaign impersonating Microsoft, NortonLifeLock, PayPal, DocuSign, and Geek Squad that uses blank-email bodies with auto-loading PDF attachments containing phone numbers, links, and malicious QR codes; victims are directed to call attacker-controlled numbers (callback phishing) or visit fake login pages, risking credential theft and malware installation. The report highlights detection evasion (PDFs that render as email content) and recommends vigilance for urgency, unexpected attachments, unknown sender addresses, QR codes, and use of active antimalware with web protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
