logo

Hackers Exploit Zoom Installer to Gain RDP Access and Launch BlackSuit Ransomware Attack

ID: 86accf1c-f3ad-5d22-9057-68e246394671

STIX ID: report--86accf1c-f3ad-5d22-9057-68e246394671

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

A nine-day, multi-stage intrusion started with a cloned Zoom installer (zoommanager.com) that installed d3f@ckloader and retrieved secondary payloads, eventually leading to deployment of BlackSuit ransomware. Attackers performed credential theft and lateral movement using Cobalt Strike and Brute Ratel, used PsExec and PowerShell for propagation, exfiltrated data via WinRAR to Bublup cloud storage, and deleted Volume Shadow Copies before encrypting files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.