RATs Distributed Through Skype, Zoom, & Google Meet Lures
ID: d8ec8cd7-b3f9-5f1e-ae1c-12e47c266238
STIX ID: report--d8ec8cd7-b3f9-5f1e-ae1c-12e47c266238
Feed Name: Zscaler Security Research Blog
This report details a multi-platform malware campaign that hosts Russian-language fake Skype, Google Meet, and Zoom sites on a shared IP to trick users into downloading malicious Android APKs (SpyNote RAT) or Windows BAT installers that retrieve and execute DCRat payloads. The attackers used domains and URL paths crafted to resemble legitimate meeting links, delivered payloads via Google Play/Windows buttons, and packed the final Windows RAT with Eziriz.NET Reactor, demonstrating active distribution of remote-access trojans through social-engineered meeting site impersonation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
