How To Do Vishing (Voice Phishing) Attacks / Scams
- Biohazard

- Jul 17
- 6 min read

How To Do Vishing Scams
These are current vishing (voice phishing) techniques used in red team operations and their complete methodology. This is an article / guide on how to do vishing (voice phishing) attacks / scams.
Phase 1: Reconnaissance (OSINT)
Everything you learn before the call determines whether you succeed. Spend most of your time here.
1A — Internal Structure
Target company:
- Organization chart (LinkedIn, ZoomInfo)
- Department naming conventions (IT, Helpdesk, Service Desk, Tech Support)
- Employee names, titles, and tenure
- Office locations and time zones
- Recent news (layoffs, acquisitions, security incidents, software migrations)
1B — Technical Infrastructure
- What VPN client does the company use? (Cisco AnyConnect, Palo Alto GlobalProtect, OpenVPN)
- What SSO provider? (Okta, Azure AD, Duo, OneLogin)
- What ticketing system? (ServiceNow, Jira, Zendesk)
- Email platform? (O365, GWS, on-prem Exchange)
- Password policy (do they enforce MFA? Expiry cycles?)
- What internal tools are commonly mentioned in job postings?
Sources:
LinkedIn job postings (reveal tech stack)
Shodan / Censys (exposed VPN portals, OWA, Citrix)
Company blog posts about internal tools
Stack Overflow / GitHub (exposed employee posts with company context)
Data from prior phishing wave (if multi-wave exercise)
1C — Target Selection
Pick targets based on:
Likelihood to answer — receptionists, helpdesk, junior staff, remote workers
Access level — IT support can reset passwords; finance can initiate transfers
Social footprint — employees who post frequently on LinkedIn are easier to research and sound natural talking to
1D — Voice Mannerism Research (Optional, Advanced)
If you have voicemail greetings, recorded company webinars, or YouTube videos featuring the person you're impersonating:
Note speech patterns (pace, filler words, regional accent)
Note tone (formal vs. casual, technical vs. business)
AI voice cloning exists but requires their explicit authorization — do not use without written consent from legal and the target individual
Phase 2: Pretext Development
The pretext is your cover story. It must be simple, urgent, and unverifiable in real-time.
Common Pretexts
Pretext | Scenario | Target |
IT Helpdesk | "We detected unusual login activity on your account at 3:47 AM. I need to verify your identity and reset your session." | Any employee |
Security Incident | "Your account was flagged sending phishing emails. I need you to verify your last login to confirm it was you." | Any employee |
Software Update | "IT is rolling out a mandatory security patch today. I need you to install it — I'll walk you through it." | Remote workers |
Vendor Support | Calling as [Microsoft/Okta/Duo] support regarding a critical security bulletin affecting your tenant. | IT staff |
CEO/Executive Impersonation | "I'm stuck at an offsite and urgently need a password reset / wire transfer." | Assistants, Finance |
Internal Survey | "We're conducting a security awareness survey — just 3 quick questions." | Any employee (info gathering) |
Pretext Checklist
Does the pretext give the target a reason to trust you (authority figure, known vendor, internal department)?
Does it create urgency (security incident, deadline, escalation)?
Is the request something the target normally does (password reset, verifying identity, installing software)?
Can the target verify your identity without hanging up and calling back? If yes, the pretext needs work
Do you have a plausible explanation for why they're being contacted directly instead of through a ticketing system?
Phase 3: Infrastructure Setup
3A — Caller ID Spoofing
Method 1: SIP Trunk / Cloud PBX
1. Sign up with a SIP provider that allows outbound caller ID manipulation
(e.g., Vitelity, VoIP.ms, Twilio — Twilio allows spoofing if you verify number ownership)
2. Configure a softphone (Zoiper, Linphone, MicroSIP)
3. Set caller ID to:
- Company main switchboard number
- IT helpdesk number
- An internal extension
4. Place test call to confirm spoofed number displays correctly
Method 2: Spoofing Apps
SpoofCard, SpoofApp, or burner VoIP apps
Less control than a full PBX, quicker to set up
Risk: some are monitored by carriers and may be blocked
STIR/SHAKEN impact (US): As of 2025-2026, STIR/SHAKEN mandates attestation levels for calls. Fully spoofed caller IDs will show "Spam Risk" or "Scam Likely" on some carriers.
Mitigations:
Use a number from the same area code as the target
Use a legitimate VoIP DID and set caller ID to a number you control (e.g., the company's publicly listed number — but this may trigger attestation failures)
Best results come from using a number within the company's own phone block (if you can acquire one)
3B — Secondary Channels
If the vishing aims to collect credentials or deliver a payload:
1. Set up phishing page (GoPhish, Evilginx2, Modlishka)
- Domain similar to company's (e.g., company-okta.com)
- Valid TLS cert (Let's Encrypt)
2. Set up SMTP relay for follow-up emails
3. Prepare the "payload" link to send via SMS/email after the call
3C — Call Recording / Note Taking
If legally authorized: record calls for reporting evidence
If not authorized: take structured notes during/after call
Template: Date, Time, Target Name, Duration, Info Revealed, Red Flags Noticed
Track per call in a spreadsheet to avoid calling the same person twice
Phase 4: Execution
4A — The Call Structure
A successful vishing call follows a scripted but flexible arc:
Opening (15 seconds):
"Hi [name], this is [fakename] from IT Security. I'm calling about a security alert on your account — do you have 2 minutes?"
Authority anchor:
State your fake title confidently
Use internal jargon (correctly)
Reference a real internal process if known
Urgency + hook (30 seconds):
"We detected a login attempt from [real IP in a major city] at [specific time]. We've temporarily locked the account, but I need to verify a few things before I can unlock it."
The ask (varies):
Goal | The Ask |
Credential harvest | "Go to portal.company-okta.com and enter your credentials to unlock" |
MFA bypass | "I'm sending a push to your phone — just approve it to confirm you're you" |
Remote access | "I need you to install this security tool — I'll email you the link" |
Information gather | "What version of [software] are you running? Can you read me the serial number?" |
Password reset | "I've initiated a password reset — your temp password is Temp2025$ — log in and change it" |
Closing:
"Thanks for your help. You'll receive a confirmation email shortly. If you get any more alerts, call the helpdesk directly."
4B — Script Flexibility
Don't read a script word-for-word — it sounds robotic. Instead:
Know your 3-5 key talking points
Be ready to answer questions (e.g., "Why didn't I get an email?")
If the target pushes back, have a graceful exit: "No problem, I'll flag this for the team to follow up — thanks for your time."
If the target is suspicious: "You're right to be cautious — you can verify by calling the helpdesk at [real number] and asking for [fake extension]. My ticket number is [random 5 digits]."
4C — Countering Objections
Objection | Response |
"I didn't get a ticket" | "This was escalated directly from the SOC — the automated alert triggered before a ticket was created. Should be in your inbox shortly." |
"Let me call you back" | "That's fine, but the account is locked until we complete verification. If you call the main line, ask for extension 423 and reference incident IR-9752." |
"This sounds like a scam" | "I appreciate that — we'd rather have cautious employees. But your account will stay locked until this is resolved. Can we take 60 seconds to sort it?" |
"I need to check with my manager" | "Understood. However, this is time-sensitive since the suspicious login came from an active session. If the account is compromised in the meantime, it'll be an incident report." |
4D — Call Cadence
For a multi-target campaign:
Wave 1 (Week 1): 5-10 exploratory calls
- Test the pretext
- Gauge employee awareness levels
- Collect internal terminology for refinement
Wave 2 (Week 2): 10-20 calls with refined pretext
- Target specific roles identified as vulnerable in Wave 1
- Escalate to credential capture or MFA bypass if in scope
Wave 3 (Week 3): 5-10 "difficult" targets
- Senior staff, IT, security team
- More sophisticated pretexting (vendor impersonation, fake emergency)Phase 5: Post-Call Actions
5A — Immediate Remediation
If credentials were collected or MFA was approved:
Notify the internal POC immediately so the employee can:
Revoke session tokens
Change passwords
Review recent account activity
Re-enroll MFA devices
5B — Documentation
Per call, document:
Target Name:
Department:
Phone Number Called:
Date & Time:
Duration:
Pretext Used:
Information Disclosed:
- [ ] Credentials
- [ ] Personal info (DOB, SSN, address)
- [ ] Internal system names
- [ ] Software versions
- [ ] MFA approved
- [ ] Remote access granted
Employee Red Flags (did they express suspicion?):
Notes:
5C — Analysis for Reporting
Quantitative metrics:
Call answer rate (targets who answered / total called)
Success rate (targets who complied / total calls answered)
Average call duration to success
Most effective pretext
Least effective pretext
Qualitative findings:
Common employee responses
Objections raised
Specific departments or roles more/less vulnerable
Policy gaps revealed (e.g., no verification process for IT calls)
Phase 6: Infrastructure Teardown
Decommission phishing domains
Tear down SIP/VoIP configurations
Dispose of call recordings (if authorized) per retention policy
Remove any VPS used for infrastructure
Tools Reference
Purpose | Tools |
SIP/VoIP PBX | Vitelity, VoIP.ms, Twilio, Asterisk (self-hosted), FreeSWITCH |
Softphone | Zoiper, Linphone, MicroSIP, Groundwire |
Caller ID spoofing | Via SIP trunk configuration, SpoofCard, Burner app |
Phishing framework | GoPhish, Evilginx2, Modlishka, Muraena |
OSINT | LinkedIn, theHarvester, SpiderFoot, Maltego, Shodan, Hunter.io |
Domain registration | Njalla, Porkbun, Namecheap (privacy-enabled) |
Voice cloning | ElevenLabs, Resemble.ai — requires explicit consent |
Note tracking | Spreadsheet, Obsidian, CherryTree, or a CRM-like tracker |






Comments