logo

'Vortax' Meeting Software Builds Elaborate Branding, Spreads Infostealers

ID: f07c712e-87a3-57e9-9db8-8a835fec0768

STIX ID: report--f07c712e-87a3-57e9-9db8-8a835fec0768

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-20

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Recorded Future's Insikt Group attributes a widespread credential-harvesting campaign to a threat actor dubbed "Markopolo," which uses a fake cross-platform virtual meeting app called Vortax to distribute infostealers (Rhadamanthys and Stealc on Windows, Atomic on macOS). The campaign leverages a convincing brand, social media, Telegram/Discord channels and reusable "Room ID" installers to target cryptocurrency users; researchers observed active distribution and recommend updating detection for Atomic, user education, stricter software controls, and monitoring for malicious domains/IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.