logo

RATs Distributed Through Skype, Zoom, & Google Meet Lures

ID: d8ec8cd7-b3f9-5f1e-ae1c-12e47c266238

STIX ID: report--d8ec8cd7-b3f9-5f1e-ae1c-12e47c266238

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details a multi-platform malware campaign that hosts Russian-language fake Skype, Google Meet, and Zoom sites on a shared IP to trick users into downloading malicious Android APKs (SpyNote RAT) or Windows BAT installers that retrieve and execute DCRat payloads. The attackers used domains and URL paths crafted to resemble legitimate meeting links, delivered payloads via Google Play/Windows buttons, and packed the final Windows RAT with Eziriz.NET Reactor, demonstrating active distribution of remote-access trojans through social-engineered meeting site impersonation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.