Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Why it matters to you
It is built to defeat mail filtering by containing nothing to filter. The defence is not technical: it is that finance and support staff know the shape of the call, and that a request to install anything during an inbound support conversation is treated as the alarm rather than as the solution.
Where we meet it
The phone side is staffed, and staffing is sold separately. Operators advertise call centre capacity by language and by hours of cover, which is why the same lure text appears against victims in unrelated countries.
Connected terms
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Quishing
Phishing delivered as a QR code, so the malicious address never appears as text anywhere a filter can read it. The code sits in an email attachment, a poster, a parking meter sticker or an invoice, and the victim resolves it with a device the organisation may not control.
OTP bot
An automated calling service that impersonates a bank or provider to trick victims into reading out their one-time codes. MFA bypass, sold as a subscription.
Read elsewhere
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.
ClickFix
A lure that tells the visitor the page is broken and asks them to fix it: copy this, press these keys, paste, run. The victim performs the delivery by hand, so nothing was downloaded and nothing was blocked.