Skip to content

Law Firms in Crosshairs: AI Phone Calls and Multi-Stage Malware Without Exploits

The point: Attackers use AI-generated phone calls and social manipulation instead of technical exploits to inject malware into law firms.

An attack campaign targeting German law firms combines AI-generated phone calls, stolen identities and multi-stage malware – without exploiting any technical vulnerabilities. The attack reveals gaps in classic detection mechanisms.

The campaign is specifically targeting German law firms and employs a multi-stage tactic: AI-supported phone calls that impersonate the identities of legitimate business partners or acquaintances, combined with the dispatch of malware via attachments. The attackers operate without exploiting CVEs or other technical vulnerabilities – they rely entirely on social engineering.

The damage does not result from unpatched systems, but from human decisions: employees receive an authentic-sounding call, are drawn into a conversation, and subsequently are sent an email with seemingly harmless files. Classic security tools that rely on exploit signatures, suspicious URLs or known malware hashes do not detect these attacks or detect them too late.

For CISOs, this presents a particular challenge: technical controls alone are insufficient. Instead, awareness training, verification protocols for unexpectedly received requests and monitoring of unusual communication patterns are necessary. Phone calls should be validated through callbacks to known numbers before responding to requests. Emails with attachments from external contacts require additional verification of the sender.


Source: www.security-insider.de · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: