top of page

How To Do Vishing (Voice Phishing) Attacks / Scams

How To Do Vishing (Voice Phishing Attacks / Scams | Black Hat HQ

How To Do Vishing Scams


These are current vishing (voice phishing) techniques used in red team operations and their complete methodology. This is an article / guide on how to do vishing (voice phishing) attacks / scams.


Phase 1: Reconnaissance (OSINT)


Everything you learn before the call determines whether you succeed. Spend most of your time here.


1A — Internal Structure


Target company:
- Organization chart (LinkedIn, ZoomInfo)
- Department naming conventions (IT, Helpdesk, Service Desk, Tech Support)
- Employee names, titles, and tenure
- Office locations and time zones
- Recent news (layoffs, acquisitions, security incidents, software migrations)

1B — Technical Infrastructure


- What VPN client does the company use? (Cisco AnyConnect, Palo Alto GlobalProtect, OpenVPN)
- What SSO provider? (Okta, Azure AD, Duo, OneLogin)
- What ticketing system? (ServiceNow, Jira, Zendesk)
- Email platform? (O365, GWS, on-prem Exchange)
- Password policy (do they enforce MFA? Expiry cycles?)
- What internal tools are commonly mentioned in job postings?

Sources:


  • LinkedIn job postings (reveal tech stack)

  • Shodan / Censys (exposed VPN portals, OWA, Citrix)

  • Company blog posts about internal tools

  • Stack Overflow / GitHub (exposed employee posts with company context)

  • Data from prior phishing wave (if multi-wave exercise)



1C — Target Selection


Pick targets based on:


  1. Likelihood to answer — receptionists, helpdesk, junior staff, remote workers

  2. Access level — IT support can reset passwords; finance can initiate transfers

  3. Social footprint — employees who post frequently on LinkedIn are easier to research and sound natural talking to


1D — Voice Mannerism Research (Optional, Advanced)


If you have voicemail greetings, recorded company webinars, or YouTube videos featuring the person you're impersonating:


  • Note speech patterns (pace, filler words, regional accent)

  • Note tone (formal vs. casual, technical vs. business)

  • AI voice cloning exists but requires their explicit authorization — do not use without written consent from legal and the target individual


Phase 2: Pretext Development


The pretext is your cover story. It must be simple, urgent, and unverifiable in real-time.


Common Pretexts


Pretext

Scenario

Target

IT Helpdesk

"We detected unusual login activity on your account at 3:47 AM. I need to verify your identity and reset your session."

Any employee

Security Incident

"Your account was flagged sending phishing emails. I need you to verify your last login to confirm it was you."

Any employee

Software Update

"IT is rolling out a mandatory security patch today. I need you to install it — I'll walk you through it."

Remote workers

Vendor Support

Calling as [Microsoft/Okta/Duo] support regarding a critical security bulletin affecting your tenant.

IT staff

CEO/Executive Impersonation

"I'm stuck at an offsite and urgently need a password reset / wire transfer."

Assistants, Finance

Internal Survey

"We're conducting a security awareness survey — just 3 quick questions."

Any employee (info gathering)


Pretext Checklist


  •  Does the pretext give the target a reason to trust you (authority figure, known vendor, internal department)?

  •  Does it create urgency (security incident, deadline, escalation)?

  •  Is the request something the target normally does (password reset, verifying identity, installing software)?

  •  Can the target verify your identity without hanging up and calling back? If yes, the pretext needs work

  •  Do you have a plausible explanation for why they're being contacted directly instead of through a ticketing system?


Phase 3: Infrastructure Setup


3A — Caller ID Spoofing


Method 1: SIP Trunk / Cloud PBX


1. Sign up with a SIP provider that allows outbound caller ID manipulation
   (e.g., Vitelity, VoIP.ms, Twilio — Twilio allows spoofing if you verify number ownership)
2. Configure a softphone (Zoiper, Linphone, MicroSIP)
3. Set caller ID to:
   - Company main switchboard number
   - IT helpdesk number
   - An internal extension
4. Place test call to confirm spoofed number displays correctly

Method 2: Spoofing Apps


  • SpoofCard, SpoofApp, or burner VoIP apps

  • Less control than a full PBX, quicker to set up

  • Risk: some are monitored by carriers and may be blocked


STIR/SHAKEN impact (US): As of 2025-2026, STIR/SHAKEN mandates attestation levels for calls. Fully spoofed caller IDs will show "Spam Risk" or "Scam Likely" on some carriers.


Mitigations:


  • Use a number from the same area code as the target

  • Use a legitimate VoIP DID and set caller ID to a number you control (e.g., the company's publicly listed number — but this may trigger attestation failures)

  • Best results come from using a number within the company's own phone block (if you can acquire one)


3B — Secondary Channels


If the vishing aims to collect credentials or deliver a payload:


1. Set up phishing page (GoPhish, Evilginx2, Modlishka)
   - Domain similar to company's (e.g., company-okta.com)
   - Valid TLS cert (Let's Encrypt)
2. Set up SMTP relay for follow-up emails
3. Prepare the "payload" link to send via SMS/email after the call

3C — Call Recording / Note Taking


  • If legally authorized: record calls for reporting evidence

  • If not authorized: take structured notes during/after call

    • Template: Date, Time, Target Name, Duration, Info Revealed, Red Flags Noticed

  • Track per call in a spreadsheet to avoid calling the same person twice


Phase 4: Execution


4A — The Call Structure


A successful vishing call follows a scripted but flexible arc:

Opening (15 seconds):


"Hi [name], this is [fakename] from IT Security. I'm calling about a security alert on your account — do you have 2 minutes?"

Authority anchor:


  • State your fake title confidently

  • Use internal jargon (correctly)

  • Reference a real internal process if known


Urgency + hook (30 seconds):


"We detected a login attempt from [real IP in a major city] at [specific time]. We've temporarily locked the account, but I need to verify a few things before I can unlock it."

The ask (varies):


Goal

The Ask

Credential harvest

"Go to portal.company-okta.com and enter your credentials to unlock"

MFA bypass

"I'm sending a push to your phone — just approve it to confirm you're you"

Remote access

"I need you to install this security tool — I'll email you the link"

Information gather

"What version of [software] are you running? Can you read me the serial number?"

Password reset

"I've initiated a password reset — your temp password is Temp2025$ — log in and change it"


Closing:


"Thanks for your help. You'll receive a confirmation email shortly. If you get any more alerts, call the helpdesk directly."

4B — Script Flexibility


Don't read a script word-for-word — it sounds robotic. Instead:


  • Know your 3-5 key talking points

  • Be ready to answer questions (e.g., "Why didn't I get an email?")

  • If the target pushes back, have a graceful exit: "No problem, I'll flag this for the team to follow up — thanks for your time."

  • If the target is suspicious: "You're right to be cautious — you can verify by calling the helpdesk at [real number] and asking for [fake extension]. My ticket number is [random 5 digits]."


4C — Countering Objections


Objection

Response

"I didn't get a ticket"

"This was escalated directly from the SOC — the automated alert triggered before a ticket was created. Should be in your inbox shortly."

"Let me call you back"

"That's fine, but the account is locked until we complete verification. If you call the main line, ask for extension 423 and reference incident IR-9752."

"This sounds like a scam"

"I appreciate that — we'd rather have cautious employees. But your account will stay locked until this is resolved. Can we take 60 seconds to sort it?"

"I need to check with my manager"

"Understood. However, this is time-sensitive since the suspicious login came from an active session. If the account is compromised in the meantime, it'll be an incident report."


4D — Call Cadence


For a multi-target campaign:


Wave 1 (Week 1): 5-10 exploratory calls
  - Test the pretext
  - Gauge employee awareness levels
  - Collect internal terminology for refinement

Wave 2 (Week 2): 10-20 calls with refined pretext
  - Target specific roles identified as vulnerable in Wave 1
  - Escalate to credential capture or MFA bypass if in scope

Wave 3 (Week 3): 5-10 "difficult" targets
  - Senior staff, IT, security team
  - More sophisticated pretexting (vendor impersonation, fake emergency)

Phase 5: Post-Call Actions


5A — Immediate Remediation


If credentials were collected or MFA was approved:


  • Notify the internal POC immediately so the employee can:

    • Revoke session tokens

    • Change passwords

    • Review recent account activity

    • Re-enroll MFA devices


5B — Documentation


Per call, document:


Target Name:
Department:
Phone Number Called:
Date & Time:
Duration:
Pretext Used:
Information Disclosed:
- [ ] Credentials
- [ ] Personal info (DOB, SSN, address)
- [ ] Internal system names
- [ ] Software versions
- [ ] MFA approved
- [ ] Remote access granted
Employee Red Flags (did they express suspicion?):
Notes:

5C — Analysis for Reporting


Quantitative metrics:


  • Call answer rate (targets who answered / total called)

  • Success rate (targets who complied / total calls answered)

  • Average call duration to success

  • Most effective pretext

  • Least effective pretext


Qualitative findings:


  • Common employee responses

  • Objections raised

  • Specific departments or roles more/less vulnerable

  • Policy gaps revealed (e.g., no verification process for IT calls)


Phase 6: Infrastructure Teardown


  • Decommission phishing domains

  •  Tear down SIP/VoIP configurations

  •  Dispose of call recordings (if authorized) per retention policy

  •  Remove any VPS used for infrastructure


Tools Reference


Purpose

Tools

SIP/VoIP PBX

Vitelity, VoIP.ms, Twilio, Asterisk (self-hosted), FreeSWITCH

Softphone

Zoiper, Linphone, MicroSIP, Groundwire

Caller ID spoofing

Via SIP trunk configuration, SpoofCard, Burner app

Phishing framework

GoPhish, Evilginx2, Modlishka, Muraena

OSINT

LinkedIn, theHarvester, SpiderFoot, Maltego, Shodan, Hunter.io

Domain registration

Njalla, Porkbun, Namecheap (privacy-enabled)

Voice cloning

ElevenLabs, Resemble.ai — requires explicit consent

Note tracking

Spreadsheet, Obsidian, CherryTree, or a CRM-like tracker


Enroll In Online Cybersecurity & Hacking Classes/Courses | Black Hat HQ

Comments


bottom of page