The Phish Zoom Signed With Its Own DKIM Key
ID: 6cb9d9f5-60d5-55fd-b291-d000da6dcb5a
STIX ID: report--6cb9d9f5-60d5-55fd-b291-d000da6dcb5a
Feed Name: IRONSCALES
An attacker created a Zoom account whose name field contained a scam script, triggered Zoom's sign-in verification email (which Zoom signed with a valid DKIM key), and then resent that legitimately signed message through a throwaway relay to a company's COO. The email displayed real Zoom branding and links, included a fabricated $986.37 PayPal charge and a callback number (+1-805-600-1572) as the sole payload (a telephone-oriented attack delivery, TOAD), bypassing link/attachment-based defenses and relying on social engineering to defraud the recipient.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
