'Vortax' Meeting Software Builds Elaborate Branding, Spreads Infostealers
ID: f07c712e-87a3-57e9-9db8-8a835fec0768
STIX ID: report--f07c712e-87a3-57e9-9db8-8a835fec0768
Feed Name: Dark Reading
Date Published: 2024-06-20
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Recorded Future's Insikt Group attributes a widespread credential-harvesting campaign to a threat actor dubbed "Markopolo," which uses a fake cross-platform virtual meeting app called Vortax to distribute infostealers (Rhadamanthys and Stealc on Windows, Atomic on macOS). The campaign leverages a convincing brand, social media, Telegram/Discord channels and reusable "Room ID" installers to target cryptocurrency users; researchers observed active distribution and recommend updating detection for Atomic, user education, stricter software controls, and monitoring for malicious domains/IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
