Freemail Fake-Invoice Callback Phishing
Freemail Fake-Invoice Callback Phishing
Since January 2026, one operator has blasted fake renewal receipts from throwaway freemail accounts, swapping the malicious link for a callback number. The message impersonates Geek Squad, Norton, McAfee, Malwarebytes, PayPal, or Amazon, shows a charge the recipient never authorized (usually somewhere between $260 and $500), and asks them to call a "billing support" line to dispute it. There is nothing to click. That is the point. Anyone who calls reaches a scripted agent who walks them into remote-access software, a bank login, or a fake refund. We tracked this cluster across tens of thousands of receipt lures over roughly four and a half months, and its infrastructure choices read as a deliberate answer to link-based and domain-based defenses.
Key Takeaways
- The operator runs a telephone-oriented attack delivery (TOAD) funnel, so the email carries no URL and URL or domain reputation has nothing to inspect; the weaponized step happens entirely on a callback line.
- Delivery rides disposable freemail accounts, overwhelmingly on gmail[.]com, split between three templated "billing" local-part families and a long tail of one-shot human-name burners.
- The durable fingerprint is a ten-digit US number trailing a receipt phrase in the subject, paired in-body with heavy digit obfuscation (letter-O for zero, lowercase-l for one, spaced digits, an injected stray x).
- Six impersonated brands appear only as body text and display-name strings, never as a matching sender domain.
- A sibling infrastructure named in Malwarebytes' June 2026 advisory runs the same lure through six burst-registered invoice[.]xyz domains, all on one registrar inside a three-day window.
Background
The hunt started from an external lead. In June 2026 Malwarebytes published an advisory, "Watch out for renewal scams pretending to be Malwarebytes," describing fake-renewal receipts that charge a victim for a subscription they never bought and route them to a callback number rather than a link. The advisory listed six dedicated invoice-themed .xyz domains and several rotating phone numbers. None of those indicators appeared in our own data, which told us the interesting thing was not the specific infrastructure but the pattern, so we pivoted the hunt to the model itself: brand-impersonation receipts, no payload link, a phone number as the only call-to-action.
That model has a name. Telephone-oriented attack delivery, or TOAD, is a hybrid email-to-voice technique in which the email is bait and the attack lives on a phone call. Because the email contains no malicious link or attachment, there is no URL for a gateway to detonate, no domain for a reputation engine to score, and no landing page for a crawler to fingerprint. Putting the callback number in the subject line sidesteps body-content filtering as well. Proofpoint's research on TOAD has estimated the technique runs at a scale of millions of attempts a month, so this is a mature category rather than a novel one.
The delivery rail matters as much as the technique. Freemail providers hand an operator free, instantly provisioned sending accounts that already pass SPF, DKIM, and DMARC, because the mail genuinely originates from the provider's own infrastructure. A fresh throwaway account per blast means that by the time any single address is reported and killed, it has already delivered. Historical sender reputation has nothing to accumulate against. The sibling .xyz domains solve a different problem: cheap, bulk-registerable gTLDs let the operator stand up short-lived, invoice-themed hostnames to serve the fake PDF, then abandon them faster than blocklists propagate.
The victim demographic is not incidental. Tech-support and fake-renewal callback fraud lands hardest on older consumers. The FBI's Internet Crime Complaint Center attributed about $1.46 billion in tech-support fraud losses across all ages in its 2024 report, of which roughly $982 million came from victims aged 60 and over. The FTC's 2024 Consumer Sentinel data book logged about 845,000 imposter-scam reports, the single largest fraud category by volume. The charge amounts in this campaign, a few hundred dollars for a "renewed" antivirus or Geek Squad plan, are calibrated to be alarming without being unbelievable to exactly that audience.
Discovery and Infrastructure
The atomic indicator here is never the freemail apex. It is the full sender address. Every gmail[.]com account is disposable, and grouping them by local-part surfaced two distinct operating styles running side by side.
The first is a set of coordinated "billing" families that reuse a fixed stem plus a variable digit tail and carry shared, on-theme display names. Three stems account for the bulk of the coordinated tier: billingportal, dexdept, and billingdept. The second style is a long tail of one-shot burners built on plausible "FirstName LastName" gmail accounts, each used for a single send and discarded. The March 2026 Malwarebytes sub-cluster belongs to this style: four human-name burners pushing "Malwarebytes" receipts for a fabricated "PC Solution" or "PC Optimizer" product.
| Family / actor | Local-part template | Display-name convention | Role |
|---|---|---|---|
billingportal<digits>@gmail[.]com |
billingportal + 3-7 digits |
literal "billing portal" / "Billing Portal" | Coordinated family, receipt lures |
dexdept<digits>@gmail[.]com |
dexdept + 3-6 digits |
"dex dept" / "Rer" / "Trc" / "Open EGV" | Coordinated family, receipt lures |
billingdept<digits>@gmail[.]com |
billingdept + digits |
human name | Coordinated family |
civilianconcurrency@gmail[.]com |
named singleton | BiIIing~Support<digits> homoglyph |
Geek Squad renewal lure |
paypalop23@gmail[.]com |
named singleton | "PayPal Pay" display spoof | PayPal transfer/hold lure |
One-shot First Last burners |
plausible human name | benign human name | Single-blast receipt lures |
No operator-owned sending or click-through domain appears in our telemetry for this cluster. The operator deliberately avoids links, so the only infrastructure it exposes is the freemail account and the phone number.
How It Works
A representative contact chain is short. A receipt lands from a freemail account whose display name reads like a billing team. The subject announces a completed order or a renewed subscription and, in the coordinated variants, carries the callback number inline: Thank you for your order - 5375983217. The body lays out an invoice: an item (an antivirus renewal, a Geek Squad plan, a "PC Optimizer"), a total in the $260 to $500 band, and a "customer care" or "helpline" number. No amount is owed and no product exists, which is exactly why the message wants a phone call rather than a click. A recipient who believes the charge and wants it reversed has only one action available: dial the number.
On the call, a scripted agent takes over. The common outcomes are remote-access software installed under the pretext of "processing the cancellation," a bank login captured to "issue the refund," or a fake accidental-overpayment routine in which the victim is convinced to send money back. The email never had to survive a sandbox because the email was only ever the introduction.
Sample Lures
All samples below show attacker-side content only. Recipient identifiers have been removed and every domain is defanged.
Malwarebytes receipt, one-shot burner (fabricated product, obfuscated callback):
From: "Amy Arlene" <abkfaggour3@gmail[.]com>
Subject: Thank you for your order - 5375983217
Body: Malwarebytes (R) Thank you for being part of us
Product: PC Solution
Total: $350.53
Customer care: 8O8 - 259 - 1351
Geek Squad auto-renewal receipt, coordinated billing family:
From: "billing portal" <billingportal095@gmail[.]com>
Subject: Payment Confirmation
Body: Receipt Confirmation
Geek Squad Subscription Auto-Renewal
[invoice layout, amount, and helpline number]
Geek Squad renewal, capital-I homoglyph display name with an embedded digit string:
From: "BiIIing~Support883992787349932" <civilianconcurrency@gmail[.]com>
Subject: PO
Body: Dear Customer, Your Geek Squad subscription has been renewed
[charge + callback number]
PayPal transfer-hold variant, brand string stuffed into the display name:
From: "PayPal Pay" <paypalop23@gmail[.]com>
Subject: PAYMENT ON HOLD
Body: Dear customer your transfer of $2600 is on hold due to
account review [callback / resend pretext]
Technical Analysis
Account-Generation Grammar
The coordinated families follow one template: a billing or department stem, then a run of three to seven digits that carry no meaning (billingportal095, billingportal235516, billingportal4311349, dexdept772, dexdept481945). The digit run exists only to mint a fresh, unique gmail address on demand. The burner tail abandons templating and pairs a plausible human name with a receipt subject, so the sender surface reads as ordinary transactional mail. Both styles converge on the same goal, a never-before-seen sender for every campaign wave.
Display-Name Grammar
Three display-name grammars run in parallel, and each is a small piece of social engineering on its own.
| Grammar class | Examples (as rendered) | Intent |
|---|---|---|
| Literal role label | billing portal, Billing Portal, BILLING DEPARTMENT, Cloud Billing Team, Norton Billing |
Mimic a transactional billing sender |
| Capital-I-for-l homoglyph + digits | BiIIing~Support883992787349932, BiIIing~Update8974865764686894 |
Render "Billing" with "ll" as "II", stuff a long digit run |
| Status-styled alarm name | BILLING_DISABLED, ACCOUNT PAUSED SYNC, 1 Update Billing to Avoid Service Interruption |
Read as an urgent system flag |
The homoglyph trick replaces the two lowercase L's in "Billing" with two capital I's, which are visually near-identical in most sans-serif clients while defeating any exact-string match on the word. The trailing digit strings double as an embedded, unclickable callback reference.
The Callback Fingerprint
The single most durable signal is a ten-digit US number trailing a receipt phrase in the subject line: Thank you for your order - 5375983217, Order received 2539185796, Your Recent Purchase Receipt 5517884029, Tech Bill No.7479868344, Order Confirmed!7175602065. In the body, that number is obfuscated to defeat naive digit extraction:
- letter O for the digit 0 (
8O8decodes to 808) - lowercase l for the digit 1 (
l35ldecodes to 1351) - single digits separated by spaces (
8 0 3 ... 5 0 9 0) - a stray injected x inside the run (
8 2 4x) - tilde or dash separators between groups
So a body callback rendered 8O8 - 259 - 1351 resolves to 808-259-1351, a number shared across three of the Malwarebytes burners, and 8 0 3 - 8 2 4x - 5 0 9 0 resolves to 803-824-5090. The numbers rotate quickly, used a handful of times each before the operator churns them.
The Sibling Invoice-PDF Registration Cohort
The dedicated-domain expression of the same operation, named in the Malwarebytes advisory and absent from our own telemetry, is a set of six invoice-themed .xyz hostnames. Public registration records show a textbook disposable cohort: one registrar, a three-day burst, identical one-year terms, a single semantic naming convention, and every name now in a registry or registrar hold state.
| Domain | Registrar | Created | Status |
|---|---|---|---|
invoicepdfin[.]xyz |
NameCheap | 2026-05-29 | clientHold (suspended) |
invoicepdfus[.]xyz |
NameCheap | 2026-05-29 | clientHold (suspended) |
invoicepdfusa[.]xyz |
NameCheap | 2026-05-31 | clientHold (suspended) |
invoicerep[.]xyz |
NameCheap | 2026-05-31 | clientHold (suspended) |
invoicestatement[.]xyz |
NameCheap | 2026-05-31 | clientHold (suspended) |
invoicestm[.]xyz |
NameCheap | 2026-05-31 | serverHold (registry-locked) |
The freemail cluster and this .xyz cohort are joined by a shared TOAD model and a shared brand lexicon, not by shared sending infrastructure. Both fabricate renewal-receipt charges in the $260 to $500 band for the same brands, both drive to a rotating callback number rather than a link, and both use the "renewed subscription you never bought" pretext. The PayPal transfer-hold variant is a separate pretext on the same rail, quoting a larger held-transfer figure rather than a small renewal charge. The .xyz shape is simply the operation run with a dedicated domain instead of link-free.
Temporal Cohorting
The earliest activity we can date is mid-January 2026, when the first rotating callback number surfaced. The two operating styles then resolve into two time cohorts. The named and homoglyph singletons and the Malwarebytes burner sub-cluster are the early group, first seen across February and March 2026. The coordinated billingportal and dexdept families cluster tightly in May and June 2026. The shift from one-shot human-name burners toward templated, higher-cadence billing account farms is the clearest change over the life of the campaign, and it points toward an operator investing in throughput.
Detection Observations
The behavioral signal is strong even though the infrastructure is thin, because legitimate transactional mail does not combine these traits. A freemail sender with a billing-team display name and a receipt subject is already unusual. Add a ten-digit number trailing that subject and the combination has almost no legitimate analogue, since real billing systems put order numbers, not phone numbers, in the subject line. The capital-I homoglyph on "Billing" and the status-styled alarm display names are near-unique to this style of lure. In the body, a brand token like "Geek Squad" or "Norton" with no matching sender domain, alongside a phone number written with letter-for-digit substitutions and injected characters, is a pattern honest senders have no reason to produce. The absence of any URL is itself the tell: this is transactional-looking mail whose only actionable element is a number to call.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The set below is a representative, export-safe subset, not the full inventory.
Senders
| Value | Role | Notes |
|---|---|---|
billingportal095@gmail[.]com |
Sender | Coordinated billing-portal family |
billingportal235516@gmail[.]com |
Sender | Coordinated billing-portal family |
billingportal277637@gmail[.]com |
Sender | Homoglyph display BiIIing~Update<digits> |
billingportal4311349@gmail[.]com |
Sender | Coordinated billing-portal family |
billingportal9082498@gmail[.]com |
Sender | Coordinated billing-portal family |
dexdept2931@gmail[.]com |
Sender | Coordinated dexdept family |
dexdept481945@gmail[.]com |
Sender | Coordinated dexdept family |
dexdept772@gmail[.]com |
Sender | Coordinated dexdept family |
billingdept8845891@gmail[.]com |
Sender | Coordinated billingdept family |
civilianconcurrency@gmail[.]com |
Sender | Homoglyph display, embedded callback digits |
paypalop23@gmail[.]com |
Sender | PayPal display-name spoof |
abkfaggour3@gmail[.]com |
Sender | Malwarebytes receipt burner (Mar 2026) |
pdapok938@gmail[.]com |
Sender | Malwarebytes receipt burner (Mar 2026) |
judikaalan22@gmail[.]com |
Sender | Malwarebytes receipt burner (Mar 2026) |
putrishanatasha@gmail[.]com |
Sender | Malwarebytes receipt burner (Mar 2026) |
| ... (representative subset; dozens of verified-malicious freemail senders) |
Domains
| Value | Role | Notes |
|---|---|---|
invoicepdfin[.]xyz |
Invoice-PDF host | External-report (Malwarebytes); burst-registered 2026-05-29 |
invoicepdfus[.]xyz |
Invoice-PDF host | External-report; registered 2026-05-29 |
invoicepdfusa[.]xyz |
Invoice-PDF host | External-report; registered 2026-05-31 |
invoicerep[.]xyz |
Invoice-PDF host | External-report; registered 2026-05-31 |
invoicestatement[.]xyz |
Invoice-PDF host | External-report; registered 2026-05-31 |
invoicestm[.]xyz |
Invoice-PDF host | External-report; registry-locked |
Phone Numbers
| Value | Role | Notes |
|---|---|---|
| +1 326-805-8864 | Callback | In-subject/body callback (rotates) |
| +1 551-788-4029 | Callback | In-subject callback ("Purchase Receipt") |
| +1 717-560-2065 | Callback | In-subject callback ("Order Confirmed!") |
| +1 253-918-5796 | Callback | In-subject callback ("Order received") |
| +1 747-986-8344 | Callback | In-subject callback ("Tech Bill No.") |
| +1 812-360-8793 | Callback | In-subject callback ("Thank you for your order") |
| +1 801-640-8589 | Callback | External-report (Malwarebytes advisory) |
| +1 804-392-2793 | Callback | External-report (Malwarebytes advisory) |
MITRE Fight Fraud Framework Mapping
This mapping uses the MITRE Center for Threat-Informed Defense fraud framework (https://ctid.mitre.org/fraud). The live scheme uses fraud-technique IDs in the F1### and FA#### ranges plus inherited ATT&CK T#### IDs.
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Establish Accounts: Email Accounts (throwaway freemail) | T1585.002 |
| Resource Development | Falsify Business Documents (fabricated invoice / receipt) | F1027 |
| Resource Development | Acquire Infrastructure: Domains (disposable .xyz siblings) | T1583.001 |
| Initial Access | Phishing (impersonation receipt email) | T1660 |
| Initial Access | Impersonate Official (brand support impersonation) | F1032 |
| Positioning | Abuse Accessibility Features (remote-access tooling on the call) | T1453 |
| Execution | Dispute Legitimate Transaction (fake-refund / overpayment) | F1024 |
| Monetization | Electronic Funds Transfer (draining the victim's bank) | F1025.003 |
Conclusion
The operator has built its whole model around removing the thing defenders are best at inspecting. No link means no domain to score, no landing page to crawl, and no payload to detonate; the fraud is committed on a phone call to a human. The infrastructure that remains, a disposable freemail account and a rotating number, is cheap to replace and carries almost no reputation history. The signal defenders retain is behavioral: the combination of a freemail sender, a billing-team persona, a receipt subject with a phone number in it, and a brand named only in the body. Watch for the templated billing families to keep scaling, and for the invoice-themed .xyz shape to surface in live traffic as the operator's next step.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.