Hiding the Callback Number: Five Variants of a TOAD Operator
Hiding the Callback Number: Five Variants of a TOAD Operator
Between January and April 2026, one callback-phishing operator ran five delivery variants with a single shared goal: keeping a phone number unreadable. The operation sent thousands of fake payment, invoice and subscription-renewal alerts from 478 one-shot Gmail accounts, impersonating PayPal, McAfee, Geek Squad and TotalAV in turn. What stayed constant was not the brand and not the pretext. It was the refusal to put the callback number anywhere a text scanner would find it. Across the five variants the number lived inside a rasterized PDF, inside a CDN-hosted image, behind a Google Drive link, and, in one case, in plain body text written with fullwidth Unicode digits separated by shade-block characters.
Key Takeaways
- The operator treated payload placement as its primary evasion variable, moving the callback number between an attached PDF, a CDN-hosted image, a Drive-hosted PDF and obfuscated body text over roughly a hundred days.
- Brand was a swappable field. Four brands rotated across the run while the account-generator families and the delivery model stayed fixed, so brand-keyword monitoring is not a durable correlator for this operator.
- One variant wrote the callback number in fullwidth Unicode digits (U+FF10 to U+FF19) separated by U+2591 shade blocks, and split brand tokens with injected spaces and zero-width joiners, defeating ASCII phone-number and brand-string matching simultaneously.
- The operation owned exactly one domain. Its call to action was a raw IPv4 address written as an IPv6-mapped literal, with the same address echoed into the sender's own localpart.
- 462 distinct display names across 478 sending identities indicates per-message randomization of the display field, not a small reused pool.
- The
customer.help<id>account-generator is shared with a second, separately tracked callback-phishing operation running a different pretext, which points to either one operator running two lines or a common burner-account supplier.
Background
Telephone-oriented attack delivery, usually shortened to TOAD and also called callback phishing, inverts the normal phishing shape. Instead of a link, the message carries a phone number and a reason to dial it: a charge the recipient does not recognize, a subscription that supposedly renewed, an invoice awaiting confirmation. The victim places the call, and the rest of the attack happens over voice, where remote-access installation, gift-card payment and bank-credential disclosure occur out of reach of email and URL controls. Proofpoint's 2024 State of the Phish put TOAD volume above ten million attacks per month, and Trustwave reported a 140% rise in callback-phishing detections between July and September 2024. The New Jersey Cybersecurity and Communications Integration Cell and Intel 471 have both published advisories tracking its persistence.
The pretexts this operator used are among the most heavily documented imposter templates in circulation. The FTC published a consumer alert on fake Geek Squad renewal scams in 2022, and the antivirus auto-renewal variant follows the same template: a fabricated renewal invoice, a callback number, then a staged overpayment that pressures the victim into returning the difference. PayPal documents the fake-invoice and money-request pretext on its own consumer-help pages, and the Pennsylvania Attorney General issued a warning about a trending PayPal invoice scam in 2025. The FBI's IC3 2024 Internet Crime Report attributes $1.46 billion in reported losses to tech support fraud for that calendar year.
Several legitimate services appear in this operation as abused infrastructure rather than as anything the operator controls:
- Gmail as the sending carrier. Free webmail supplies disposable sending identities in minutes with no domain to register and no history to build. Because the mail genuinely originates from Google's servers, it passes SPF and DKIM for
gmail[.]comlegitimately. Those checks confirm that Google sent the message, not that the account or its contents are trustworthy. - cdn.jsdelivr[.]net, a free public CDN that mirrors any public GitHub repository and serves individual files over HTTPS under the
/gh/<user>/<repo>@<branch>/path scheme. Anyone can create a throwaway repository, drop an image into it, and have a high-reputation CDN front it instantly. Proofpoint has documented GitHub service abuse for phishing, and both Hackread and Check Point have reported jsDelivr serving phishing-linked content. - drive.google[.]com share links. Any account can publish a file to a link-viewable URL under a universally trusted Google domain, then swap or remove the hosted lure after delivery.
- shorturl[.]at, a public shortener, appeared once as a redirect layer.
None of these platforms is operator-controlled, and none can be treated as an indicator. The abuse sits at the account and repository path, not at the host.
Discovery and Infrastructure
The operation is unusually infrastructure-light. Of 478 sending identities, 477 are Gmail accounts sending direct Gmail SMTP with no relay, no ESP and no return-path domain of their own. The single exception is zunoravexl[.]com, an operator-registered apex used for four messages on one day.
| Indicator | Role | Notes |
|---|---|---|
zunoravexl[.]com |
Sending apex, CTA | Namecheap, WHOIS privacy, created 2026-01-22, first observed 2026-02-13 |
190.2.146[.]19 |
CTA endpoint | Reached as an IPv6-mapped literal; not shared hosting |
cdn.jsdelivr[.]net |
Lure-image host | Abused CDN, never an indicator; abuse is at the /gh/ repo path |
drive.google[.]com |
Lure-PDF host | Abused Google hosting, never an indicator |
The three-week gap between registration and first use of zunoravexl[.]com is consistent with a pre-staged burner apex held before activation. Its label is algorithmic nonsense with no matching business and no brand-token collision, which distinguishes it from the brand-squat and typosquat construction more common in this pretext family.
Within the Gmail burner cohort, sending identities cluster into six localpart generator families:
| Generator family | Distinct senders | Example form |
|---|---|---|
| Random / dictionary-word | 363 | nadiavestal002@, dominationdominating834@ |
customer.help<id> |
79 | customer.help860528@ |
money.received<id> / money.transaction<id> |
10 | money.received8510105f@ |
customer<id> / customerh<id> |
6 | customer567t@, customerh525@ |
hlpcstmr<id> |
3 | hlpcstmr13gxa@ |
no.reply<id> |
3 | no.reply049893iy@ |
Five GitHub throwaway accounts hosted lure images across six repositories for the CDN variant, one repository per message: pritom7w (repositories paypal2 and pay66), paypal1230 (invoicealert), shuvomondol02-cpu (paypal), ashishbiswas229950-ai (ABP), and edgardavids0789 (tylerdurden3). Because the CDN host carries no operator signal, these handles are the durable pivot for that variant.
How It Works
Every variant converges on the same endgame. The recipient reads about money they did not spend, finds a support number, and calls it. The operator's design problem is getting that number in front of a human without letting a machine read it, and each variant answers that problem differently.
The highest-volume form is the simplest. The email body is empty, there is no link anywhere in the message, and the entire payload is an attached PDF wrapping a JPEG screenshot of a fabricated PayPal invoice. The callback number exists only as pixels. All but a handful of the operation's messages carry no readable body text at all, which makes the subject line the only text the operator has to work with, and it is used as the lure: a long run-on string built from a bracketed pseudo-reference code, a fabricated company name, and an assertion that invoice verification is required.
A later variant abandons the attachment and writes the number into the body, but not in ASCII. The renewal notice below uses fullwidth Unicode digits separated by shade blocks for the phone number, and splits brand tokens with injected spaces.
Sample Lures
All samples are redacted. Recipient identifiers have been replaced with placeholders and every host is defanged.
Email, PayPal invoice-verification pretext (attached-PDF variant). Empty body, no link; the payload is the attachment.
From: "George" <nadiavestal002@gmail[.]com>
Subject: [transaction alert] [D-20MVP26] - logged via PayPal signup associated
with [company] delivery mailbox on January 27, 2026. Invoice
verification is required for registration.
Body: (empty)
Attach: invoice.pdf (PDF wrapping a JPEG of a fabricated PayPal invoice;
callback number rendered inside the image)
Email, antivirus auto-renewal pretext (fullwidth-digit variant). The callback number is written in fullwidth Unicode digits separated by U+2591 shade blocks.
From: "Customer Support" <customer.help5214685@gmail[.]com>
Subject: Payment confirm via [name]
Geek Webkit Squad Auto-Renew Enabled - Cancel Anytime!
Invoice # : #2215147464 Payment: Online
Howdy, [recipient email] , Date - 14.03.2026
Your Geek plan has been renewed successfully. The transaction has been
completed and the updated plan details are available in your dashboard.
SUBSCRIPTION OVERVIEW Payment Status : Completed
Service : Total AV Disc Tenure : 12 Month Service
License key : 2215147464 Invoice # : SM2215147464
Device : Mac & Windows Total Value : $546.10
For support or cancellations, call : 804 ░ 735 ░ 4978
"Geek Webkit Squad" is an invented support entity, not a real company. It fuses the name of a genuine retail support brand with a browser-engine word, while the service field names a real antivirus product. Both brands are impersonated here.
Email, McAfee transaction-alert pretext (IP-literal variant). The only variant sent from an operator-owned domain, and the only one whose CTA is a bare address.
From: <190.2.146.19mcafee_security@zunoravexl[.]com>
Subject: [Transaction Alert] [TXN-/ID/QWZ#R4T/BN9E/7D21] - Invoice ...
CTA: http[:]//[0000:0000:0000:0000:0000:ffff:be02:9213]/qs=r-[token]
Email, generic invoice pretext (Drive-link variant). The body is padded with random alphanumeric token pairs rather than left empty.
From: "Memo" <customer.help597614@gmail[.]com>
Subject: Memo
v95zd8u 520 nrbmczp 3370 2w9a9 [filler continues]
CTA: http[:]//drive.google[.]com/file/d/[file-id]/view?usp=sharing
Technical Analysis
Payload Placement as the Evasion Variable
Most phishing operators iterate on copy. This one iterated on where the payload physically sits. Over roughly a hundred days the callback number moved four times, and each move traded one exposure for another.
| Variant | Window | Payload placement | Distinguishing mechanic |
|---|---|---|---|
| Attached-PDF core (PayPal) | Jan 20 to Feb 23 | PDF attachment wrapping a JPEG | Empty body, no URL; number rasterized as pixels |
| IP-literal CTA (McAfee) | Feb 13 | URL | IPv6-mapped IPv4 literal; same IP echoed in sender localpart |
| jsDelivr CDN image (PayPal) | Mar 11 to Mar 16 | CDN-fronted GitHub repository | One throwaway GitHub account and repository per message |
| Fullwidth-digit body (Geek Squad, TotalAV) | Mar 14 to Mar 18 | Plain body text, no URL | Fullwidth Unicode digits, shade-block separators, space-split brand tokens |
| Drive-link PDF (generic invoice) | Apr 22 to Apr 29 | Google Drive share link | Random filler-token pairs padding the body |
The March window is the most instructive. The CDN-image variant and the fullwidth-digit variant ran concurrently, four days apart, on the same account-generator. The operator was running two answers to the same problem in parallel rather than migrating sequentially from one to the next.
Fullwidth-Digit and Space-Injection Obfuscation
Unicode code points U+FF10 through U+FF19 are fullwidth forms of the ASCII digits. They render to a human reader as ordinary numerals but occupy different code points, so a pattern built on ASCII character classes does not match them. Interleaving them with U+2591 light-shade blocks adds a second layer: even a matcher extended to the fullwidth range has to tolerate non-numeric separators between digit groups.
Rendered to the reader: 804 ░ 735 ░ 4978
Code points: U+FF18 U+FF10 U+FF14 U+2591 ...
Recovered value: 804-735-4978
The same thinking is applied to brand strings. Geek W ebkit Squad and T o t a l A V survive human reading while breaking substring matching, and elsewhere in the operation zero-width joiners sit between every character of a phrase. Recovering the numbers requires matching on the fullwidth digit class and transliterating it back to ASCII, which is a small change to make and easy to miss entirely if nobody thinks to look.
The IPv6-Mapped IPv4 Literal
::ffff:a.b.c.d is standard IPv4-mapped IPv6 notation, in which the low 32 bits carry an ordinary IPv4 address. Written in hex inside brackets, the operator's CTA decodes cleanly:
http[:]//[0000:0000:0000:0000:0000:ffff:be02:9213]/
be02:9213
0xBE=190 0x02=2 0x92=146 0x13=19
190.2.146[.]19
The link is valid and connects over IPv4 in practice, but it contains no dotted quad and no domain name, so an extractor built around a \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3} pattern or a domain lookup does not recognize it as an IP-based URL. SANS Internet Storm Center has documented this notation in banking phishing, and Malwarebytes reported it in a March 2026 campaign. What makes this instance distinctive is the self-reference: the operator wrote the same address into its own sender localpart, 190.2.146.19mcafee_security@, producing a fingerprint that is unlikely to recur by coincidence.
Generated Content Structure
The fabricated invoices reuse a single generated digit string across the invoice number, order number and licence-key fields of a given message, applying an SM prefix to one of the three. Three fields that should be independent identifiers are one identifier wearing three hats, which is a reliable structural tell in the rendered notice.
Subject-line reference codes follow a two-tier grammar despite full per-message randomization. One bracket group carries a plain-English tag drawn from a small fixed vocabulary: [Transaction Alert], [Trade Alert], [Transaction Notification], [kindly information], [Automatic Alert], [Detailed information]. A second carries a pseudo-reference code built as a short alphabetic prefix, a hyphen, then a mixed alphanumeric token, often slash-delimited: [C-2026MVP26#01], [CE-7442PLQ66#313], [AP-FNB/TRX/VNR/RO7DX7C77Y], [B-SRKK26541289L#05]. The vocabulary is small and the shape is stable even though no two codes repeat.
Display names are randomized per message rather than drawn from a pool. 462 distinct display names across 478 sending identities is close enough to one-to-one to rule out a small reused set. The values fall into three shapes: a single random first name presented as a personal notification, the literal strings Customer Support or Customer Help, and the subject text duplicated into the display field.
Cross-Operation Overlap
The customer.help<id> generator is not exclusive to this operation. Five accounts in that namespace carry the antivirus-renewal pretext that belongs to a second, separately tracked callback-phishing operation with its own distinct sending families. Two readings fit the evidence and our data does not separate them: one operator running two pretext lines, or two operators sourcing burner accounts from the same supplier. The recovered callback numbers do not overlap between the two, which mildly favours the supplier reading. We have not asserted a single operator on this basis, and the overlap is recorded as an observation rather than an attribution.
Detection Observations
The signals that distinguish this traffic from legitimate mail are structural rather than lexical.
- A freemail sender combined with an empty body, no extractable URL, and a PDF attachment is an unusual shape for genuine transactional mail, which almost always carries readable text and a link to a real account portal.
- The presence of fullwidth Unicode digits in a body sent from a consumer freemail account and carrying a receipt or renewal pretext is a high-precision indicator. Fullwidth digits are ordinary in Japanese commercial email, so the signal only holds when scoped to that combination.
- A brand name split by injected spaces or zero-width joiners, in a message that otherwise reads as a renewal notice, is an intentional-obfuscation signal on its own. Legitimate senders have no reason to fragment their own brand.
- URL literals in bracketed IPv6 form deserve normalization to their IPv4 equivalent before any reputation lookup, since the bracketed form carries neither a domain nor a dotted quad.
- Invoice, order and licence-key fields sharing one digit string, with a two-letter prefix on one of them, distinguishes a generated notice from a real receipt.
- Account-generator regexes for this operator need a digit anchor immediately after the prefix. An unanchored
customerprefix collides with ordinarycustomercare-style addresses used by real organizations, and that collision produces persistent noise. - Per-message randomization of the display name means display-name reputation carries no signal here. The generator families in the localpart do.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped to post-access fraud behavior, so this mapping is an alignment by analogy: the campaign is a pre-access lure, and its monetization stage happens over the phone rather than through an account the operator has entered. Unmapped stages are noted rather than forced.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development (TA0042) | Create Fake Materials: Fake Documents | F1020.001 |
| Initial Access (TA0001) | Phishing | T1660 |
| Initial Access (TA0001) | Impersonate Official | F1032 |
| Stealth (TA0005) | Payload placed outside machine-readable text: rasterized attachment, CDN-hosted image, fullwidth-digit body text, IPv6-mapped IPv4 literal CTA | |
| Positioning (FA0001) | Remote Access Tools | T1219 |
| Monetization (FA0002) | Refund and overpayment fraud conducted over the voice channel; no discrete F3 technique |
T1660 and T1219 are ATT&CK-inherited techniques carried in the F3 export. The Stealth and Monetization rows describe observed behavior for which F3 v1.1 carries no discrete technique, and the ID cells are left blank rather than filled with an invented identifier.
Indicators of Compromise
All indicators below are defanged. Victim data has been removed.
Senders
| Value | Role | Notes |
|---|---|---|
190.2.146.19mcafee_security@zunoravexl[.]com |
Sender | Operator apex; McAfee pretext; IP echoed in localpart |
customer.help315864@gmail[.]com |
Sender | CDN-image variant |
customer.help4344k@gmail[.]com |
Sender | CDN-image variant |
customer44hkpp@gmail[.]com |
Sender | CDN-image variant |
g5u756ehw4y3q@gmail[.]com |
Sender | CDN-image variant |
gerdabulomrdahuko3793@gmail[.]com |
Sender | CDN-image variant |
hegdhshhsgdhdehgdhdhdhd63737@gmail[.]com |
Sender | CDN-image variant |
customer.help050216@gmail[.]com |
Sender | Fullwidth-digit renewal variant |
customer.help5214685@gmail[.]com |
Sender | Fullwidth-digit renewal variant; callback 804-735-4978 |
customer.help5454gh@gmail[.]com |
Sender | Fullwidth-digit renewal variant; callback 808-865-6158 |
customer.help6553713@gmail[.]com |
Sender | Fullwidth-digit renewal variant |
customer.help9861963552@gmail[.]com |
Sender | Fullwidth-digit renewal variant |
customer.help409276@gmail[.]com |
Sender | Drive-link variant |
customer.help597614@gmail[.]com |
Sender | Drive-link variant |
| … | Representative subset. The operator's verified sending inventory runs to 500+ accounts |
Domains
| Value | Role | Notes |
|---|---|---|
zunoravexl[.]com |
Sending apex, CTA | Namecheap, WHOIS privacy, created 2026-01-22 |
Hosts / IPs
| Value | Role | Notes |
|---|---|---|
190.2.146[.]19 |
CTA endpoint | Reached as [0000:...:ffff:be02:9213]; not shared hosting |
Phone Numbers
Operator callback numbers only. Recipient numbers are excluded.
| Value | Role | Notes |
|---|---|---|
804-735-4978 |
Callback | Recovered from fullwidth-digit obfuscation |
808-865-6158 |
Callback | Recovered from fullwidth-digit obfuscation |
The callback numbers for the attached-PDF and CDN-image variants remain unrecovered. In both, the number exists only as pixels inside a PDF or JPEG, so recovering it would require optical character recognition over the attachment.
Conclusion
This operator spent four months answering one question: where can a phone number sit so that a person reads it and a machine does not. Rasterizing it, hosting it on a reputable CDN, and rewriting it in a different Unicode block are three answers to the same question, and the operator ran the last two simultaneously rather than in sequence. Defenders tracking callback phishing should expect payload placement to keep migrating and should treat the container as the thing worth fingerprinting, because the brand on the invoice changed four times while the delivery machinery barely moved.
Sources
- Keepnet, TOAD Explained and Defense (citing Proofpoint 2024 State of the Phish and Trustwave Q3 2024 data)
- NJCCIC, TOAD Attacks Continue to Hop Along
- Intel 471, To Deliver Malware, Attackers Use the Phone
- FTC, How to recognize (and avoid) a fake Geek Squad renewal scam
- PayPal, What are invoice scams and money request scams on PayPal?
- Pennsylvania Office of Attorney General, warning on a trending PayPal scam (2025)
- Proofpoint, How Threat Actors Abuse GitHub Service for Phishing
- Hackread, Global CDN Service jsDelivr Exposed Users to Phishing Attacks
- Check Point, CDN Service Exposes Users to Malicious Packages for Phishing Attacks
- SANS ISC, eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address
- Malwarebytes, Phishers hide scam links with IPv6 trick in free toothbrush emails (March 2026)
- FBI, 2024 Internet Crime Complaint Center Report
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.