New Phishing Attack Mimic as Zoom Meeting Invites to Steal Login Details
A phishing campaign has emerged, targeting corporate users with fake Zoom meeting invitations. These emails appear to originate from colleagues, leveraging the popularity of virtual meetings. The phishing emails use social engineering tactics to create…
A phishing campaign has emerged, targeting corporate users with fake Zoom meeting invitations. These emails appear to originate from colleagues, leveraging the popularity of virtual meetings. The phishing emails use social engineering tactics to create urgency, encouraging recipients to click on malicious links.
Once the links are clicked, users are directed through a sequence designed to harvest Zoom login credentials. The emails mimic official Zoom meeting notifications, using familiar branding and language to prompt an immediate response.
The attack follows a five-stage process. Initially, victims receive a phishing email with a link that mimics Zoom’s interface. The page transitions to a pre-recorded video of "participants" in a meeting, simulating a live conference call.
A phishing campaign has emerged, targeting corporate users with fake Zoom meeting invitations.
Subsequently, users receive a fake disconnection notification followed by a fraudulent login prompt intended to capture credentials. The attack utilizes multiple domains, with tracking through specific subdomains and meeting pages hosted on other services.
Network traffic analysis shows credentials are transmitted via Telegram API endpoints, enabling attackers to collect information in real-time while maintaining operational security through common communication channels.
Based on reporting by Cyber Security News.
