Buying fake Justin Bieber tickets could see your phone infected with malware


Scammers are increasingly leveraging call centers to carry out cyberattacks and infect their victims with malware after first roping them in by using PayPal invoices and even tickets to Justin Bieber’s upcoming 2022 world tour as lures, experts have warned.
According to a new report from Proofpoint, the firm’s security researchers have observed an increase in attacks that rely on victims to call scammers directly and initiate the interaction after receiving an email with their phone number.
However, there are two types of these attacks, with one using free remote assistance software to steal money while the other, which is frequently associated with BazaCall, uses the BazaLoader malware disguised as a document to compromise a victim’s computer and gain access to their online accounts.
Bieber fakes
In recent attacks, threat actors have begun emailing victims claiming to be representatives from Justin Bieber ticket sellers, computer security services, Covid-19 relief funds or online retailers with the promise of refunds for mistaken purchases, software updates or financial support. These emails contain a phone number for customer assistance but when a victim calls for help, they are instead connected with a malicious call center attendant who begins the attack.
What’s clever about this new attack method is that by having victims call on their own accord, scammers are able to bypass some automated threat detection services which are only capable of flagging malicious links or attachments in emails.
Call center lures
One of Proofpoint’s researchers recently identified a financially motivated telephone-oriented attack delivery (TOAD) threat that mimicked a PayPal invoice from a weapons manufacturer in the US. After calling the number on the invoice, the researcher was told to download AnyDesk and login to his bank account.
With Justin Bieber’s 2022 Justice World Tour set to begin in February of next year, Proofpoint said it has seen the Canadian pop star being used quite frequently as a lure associated with BazaCall threats.
After calling the number on a fake ticket invoice, the firm’s researcher was put on hold with Bieber’s music playing in the background. Once the scammer got on the line, they claimed that someone had erroneously placed an order on the researcher’s credit card and by going to ziddat[.]com/code.exe, a refund could be issued. After visiting the site, the BazaLoader malware was successfully downloaded on the researcher’s virtual machine.
What makes call center-based email threats so dangerous is that the scammers behind them don’t specifically target victims based on demographics, jobs or location but likely procure their contact information from legitimate data brokerages or other telemarketer resources. Proofpoint is aware of victims losing nearly $50k in one attack with the threat actor pretending to be a representative from NortonLifeLock.
In addition to PayPal and Justin Bieber, call center-based email threat campaigns often impersonate a number of popular brands including Norton, MacAfee, eBay, GeekSquad, Santander Bank, Amazon, Symantec and others.
To prevent falling victim to these sorts of attacks, users should remain vigilant when checking their email and avoid calling the phone numbers contained in any suspicious emails, especially for items they didn’t purchase.
Protect your identity and data online with the best antivirus software, the best malware removal software and the best identity theft protection tools
Scammers are increasingly leveraging call centers to carry out cyberattacks and infect their victims with malware after first roping them in by using PayPal invoices and even tickets to Justin Bieber’s upcoming 2022 world tour as lures, experts have warned. According to a new report from Proofpoint, the firm’s security…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010