Skip to main content
BazarCall: Callback Phishing to Remote Access operation cover
COMING SOONIntermediatePRO

BazarCall: Callback Phishing to Remote Access

An accounts-payable coordinator received a spoofed subscription invoice with no attachment and no link -- just a phone number to call. The call center talked her into installing a remote-management tool, and from there the operator moved fast: enumeration, a persistence scheduled task, a Cobalt Strike stager, and a pivot attempt toward the domain controller. Reconstruct the chain from the lure email through the RMM session and the second-stage beacon.

55m
6 tasks
50 points
Pro

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

EmailXDRSIEM

What you'll investigate

6 objectives unlock when this operation goes live.

1Trace the lure
2Name the tool that opened the door
3Identify the persistence mechanism
4Track down the staging domain
5Confirm the second-stage payload
6Determine the intended next target

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.

Get Started Free