Bypassing Multi Factor Authentication (MFA) with a callbot

Thomas Le Coz

Thomas Le Coz

Phishing

Most of the time, vishing requires a skilled operator to manipulate people.

Attackers need to not only be skilled, but also speak the language of the victim.

However, we found call bots attacks to be very popular to circumvent MFA: by having an automated bot call people and ask for the One Time Password (OTP) after credentials has been entered.

This is a prototype we built as a proof of concept.

Most bots are controlled through Telegram channels and will output the data on top of stealing cookies and setting up persistent access through specific Telegram commands.

Video demonstration

Don't miss an article

No spam, ever. We'll never share your email address and you can opt out at any time.