Spoofed Zoom, Google & Skype Meetings Spread Corporate RATs
ID: d6fdb4a2-60c7-5236-a3fd-ab8d44086857
STIX ID: report--d6fdb4a2-60c7-5236-a3fd-ab8d44086857
Feed Name: Dark Reading
Date Published: 2024-03-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers from Zscaler ThreatLabz uncovered an ongoing campaign that impersonates popular meeting platforms (Skype, Google Meet, Zoom) using lookalike domains and hosted payloads to distribute Android and Windows RATs (SpyNote, NjRAT, DCRat). The attackers used convincing URLs and downloadable binaries (e.g., Skype8.exe, Skype.apk, driver.exe, meet.exe) to deliver info-stealing and remote-access capabilities; the report includes observed indicators, delivery techniques, and mitigations such as patching and defensive controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
