Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Threats Targeting VoIP Networks As Usage Surges During Pandemic
Articles

Threats Targeting VoIP Networks As Usage Surges During Pandemic

ISBuzz TeamBy ISBuzz TeamOctober 23, 2020Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Voip
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Internet service providers are seeing a spike in Voice-over Internet Protocol (VoIP) usage driven by the increased adoption of working from home during the COVID-19 pandemic. This has been reported by many companies in the space including Comcast, which has said that VoIP and video conferencing usage is up 210-285 percent since the start of the pandemic. With this in mind, it’s important to remember that whether VoIP systems are maintained internally or outsourced to a third-party vendor, they remain an extension of organizations’ attack surface that can fall victim to attackers.

VoIP systems are vulnerable to many threats including denial-of-service, metadata theft, traffic interception, and premium number scams. Threat actors can also use an insecure VoIP system as an entry point to compromise more sensitive networks or to divert attention from malicious activity elsewhere. Despite these vulnerabilities, VoIP systems do not typically receive much attention from IT departments. These systems often retain default or shared credentials and they may be overlooked when searching for and fixing vulnerabilities. So even though VoIP infrastructure plays a key role in business operations, the issue for many enterprises remains whether they would notice VoIP malware at all.

Mandiant Threat Intelligence often finds adversaries attempting to gain access to VoIP administrator user accounts through stolen or brute-forced credentials. These credential collection tools are widely accessible, meaning actors without sophisticated development expertise can compromise VoIP infrastructure. Given the breadth of activity facilitated by VoIP compromise, network defenders should consider the following possible outcomes for attackers.

Metadata Targeting and Voicemail Theft

VoIP calling systems generate voice recordings and related metadata that is sought after by espionage- and financially motivated actors. In September 2020, ESET researchers discovered a new and rare piece of Linux malware dubbed “CDRThief” being used in attacks targeting VoIP telephony switches in campaigns designed to steal call metadata. In August 2019, Microsoft reported APT28 attempting to compromise VoIP-based phone systems as well as other Internet of Things devices. Mandiant Threat Intelligence observed threat activity we believe used FINSPY variants capable of capturing VoIP file recording, and in a separate campaign, espionage actors sent a phishing email that included a legitimate voicemail message, possibly stolen from a corporate VoIP service.

Premium Number Fraud 

‘Call pumping’ scams are one of the most common threats to companies from compromised VoIP systems. The Communications Fraud Control Association recently estimated the losses associated with premium number fraud, or International Revenue Share Fraud (IRSF), to be between $4 billion and $6.1 billion. The scheme involves making calls from compromised phone systems to phone numbers that bill callers. The actor registers a premium call number, often overseas to charge higher rates, where they receive a cut of the charges. They then will have compromised phone systems call these premium numbers, running up charges on the victim’s account.

These scams can cost affected companies millions of dollars in illegitimate premium number charges in a short period, making it attractive to cybercrime actors. The malicious actors will often choose premium number services that bill and pay out on a weekly schedule, while most phone companies bill monthly. This way the actor can run up significant charges before the fraud is discovered.

Telephony Denial-of-Service 

VoIP phone systems are vulnerable to telephony denial-of-service (TDoS) attacks, where a large number of illegitimate calls prevents legitimate calls from going through. VoIP systems are also potentially vulnerable to denial-of-service conditions from additional vectors, including being flooded with “invite” requests, “goodbye,” or “unavailable” messages or similar flooding attacks. This technique is high-volume and hard to miss, which can be advantageous for attackers—these systems can be used as diversionary measures to burden network defenders while other fraud activity is taking place.

Call Manipulation

A successful man-in-the-middle (MitM) attack that enables call manipulation could be used to facilitate almost any phone-based social engineering activity, including vishing (voice-based phishing) or bypassing phone-based authentication methods. For example, if a malicious actor compromised a bank’s phone system, they could redirect incoming calls from customers to instead connect to attacker-controlled infrastructure and, under the guise of verifying the customer’s identity, compromise their account. A malicious actor could also redirect a call from a financial institution to a customer attempting to confirm a transaction and impersonate the customer to confirm the transaction.

Extortion: The Future of VoIP Abuse?

The compromise of VoIP infrastructure can provide actors with access to sensitive corporate information and empower them to drive denial-of-service conditions. Actors have historically used this to fuel extortion attacks, as seen with the adoption of public data disclosure websites for victims of ransomware. Even the theft of large volumes of call data may be more susceptible to extortion as automated transcription and processing of audio files could help actors identify sensitive business data quicker.

Mitigation Considerations

The biggest step an enterprise can take to mitigate risks for VoIP is to seriously consider VoIP infrastructure as part of the attack surface, regardless of whether it is managed internally or by a third-party. Simply put, VoIP infrastructure is an extension of IT infrastructure, and as such it demands monitoring, maintenance and auditing like any other area. Here are some tips on how to protect VoIP networks:

  • Firmware for VoIP phones and infrastructure should be patched regularly, and passwords should be changed from the default.
  • Multifactor authentication should be required to access VoIP accounts, especially those with administrative privileges.
  • Calls to international or premium numbers can be restricted to defeat call pumping schemes, and elements such as duration, frequency and time placed should be monitored for outliers and patterns of abuse.
  • Having VoIP phones run on a separate network can prevent a compromised phone from exposing data sent over the network or providing access to other machines on the network.
  • Organizations should have a plan for communication methods in the event VoIP systems are unavailable—either through TDoS activity or other denial-of-service scenarios such as ransomware or destructive malware.

The pandemic has caused more employees to work from home than ever before. This scenario has driven VoIP usage upwards during the pandemic and provided a reminder of how reliant most of us are on global connectivity. Malicious actors can, and will, seize upon this dependency to damage business operations, distract from the incident response work of security teams, and profit from fraud. Organizations cannot afford to leave VoIP infrastructure out of their defensive operations.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}