logo

Malware operators Zoom’ing in

ID: 188c5e2b-8e84-5204-bef4-12f9966222ff

STIX ID: report--188c5e2b-8e84-5204-bef4-12f9966222ff

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2020-04-16

Date Updated: 2026-04-27

Author: Joshua Kim

...
...

This report documents a drive-by malware campaign where attackers host a malicious Zoom installer (zoom-free2.com) that drops a legitimate Zoom binary and nanohost.exe (an ARKEI/VIDAR infostealer). The infostealer performs system and hardware reconnaissance, harvests browser and FTP credentials, performs geolocation lookups via ip-api.com, downloads additional DLLs from its C2 (wrangellse.com), and exfiltrates collected data; the report provides hashes, file paths, network IOCs, a YARA detection, MITRE ATT&CK mappings, and recommended mitigations such as downloading Zoom only from the official site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.