Article img

CFC warns of new “BazarCall” ransomware attack method

CFC warned brokers and their clients of an emerging method of ransomware attack – dubbed ‘BazarCall’ – which is targeting small businesses...

According to CFC’s in-house cyber threat analysis team - the ‘BazarCall’ attack method has been growing in use among well-known ransomware groups and is responsible for an increasing number of malware infections observed by CFC over the past three months.

Uniquely, the BazarCall method subverts common cyber security controls by utilizing a phishing email that tricks the victim into phoning a call centre - rather than clicking a link - and instructing them to download malicious software and infect their own computers. From there, the hackers can carry out their ransomware attacks undetected.

“Making the victim do all the heavy lifting is a notable shift from the more traditional hacking attack vectors” said Tom Bennett, CFC’s cyber threat analysis team leader. “Unfortunately most workplace education around phishing emails doesn’t warn about this type of social engineering, so it represents a significant new threat.”

According to Bennett, BazarCall accounted for nearly 10% of the malware incidents CFC has detected across its own portfolio over the last three months, but to date the company has been able to prevent cyber claims stemming from these infections.

To do so, CFC’s cyber threat analysis team proactively detects threats and intervenes on behalf of its cyber customers: in the case of BazarCall, CFC’s team can identify whether a specific victim at the organization has received the BazarCall phishing email; whether that victim has called the phone number within the email; and if the malware has been installed on their system.

“To date we have detected and removed every case of this malware within our impacted customers, at no cost to them,” continued Bennett. “But we must all remain vigilant – cyber criminals are motivated, well-funded and well-organized. And they are constantly revising their attacks. That’s why we’ve built our dedicated cyber security team to help our customers protect themselves and prevent incidents before they happen.”

See more
See less
Share fluctuations
Sompo
31.0
USD
-3.2%
Tokio Marine
30.2
USD
-3.1%
MS&AD
26.5
USD
-2.5%
Hannover Re
43.4
USD
-1.6%
IGI
12.5
USD
-1%
Ryan Specialty
54.0
USD
-0.7%
WTW
272.0
USD
-0.6%
Truist
37.2
USD
-0.6%
Brown & Brown
84.9
USD
-0.4%
AXA
36.5
USD
-0.4%
QBE
11.3
USD
-0.4%
RenaissanceRe
24.8
USD
0%
See more
See less
Upcoming events