Malware operators Zoom’ing in
ID: 188c5e2b-8e84-5204-bef4-12f9966222ff
STIX ID: report--188c5e2b-8e84-5204-bef4-12f9966222ff
Feed Name: Expel Blog
This report documents a drive-by malware campaign where attackers host a malicious Zoom installer (zoom-free2.com) that drops a legitimate Zoom binary and nanohost.exe (an ARKEI/VIDAR infostealer). The infostealer performs system and hardware reconnaissance, harvests browser and FTP credentials, performs geolocation lookups via ip-api.com, downloads additional DLLs from its C2 (wrangellse.com), and exfiltrates collected data; the report provides hashes, file paths, network IOCs, a YARA detection, MITRE ATT&CK mappings, and recommended mitigations such as downloading Zoom only from the official site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
