Zoom Users Under Threat Once Again, Phishing Campaign Aims to Steal Zoom Credentials: Report

Zoom users are getting phishing emails, asking them to login with their credentials on fake websites.

Advertisement
By Vineet Washington | Updated: 22 April 2020 12:49 IST
Highlights
  • Zoom users may be under threat of phishing emails
  • These emails ask users for their credentials
  • Hackers are targeting Zoom users owing to the massive userbase

Zoom phishing emails seem to link users to a “spoof page”

Photo Credit: Proofpoint

Zoom is a rapidly growing video conferencing service that is being used by more than 200 million users. But the service has been in the news for all the wrong reasons, including security flaws and vulnerabilities. Now, another threat to Zoom users has been reportedly spotted. Hackers are using credential phishing emails to gain access to Zoom users' account details. According to a report, hackers are targeting individuals and businesses in the transportation, manufacturing, technology, business, and aerospace sectors in the US.

Owing to the ongoing coronavirus pandemic, offices, schools, and other organisations have switched to video conferencing as a means of communication. This has led to the massive increase in user base for services like Zoom.

In an analysis published by Proofpoint, it was found that credential phishing is being used to gain access to user account details. Phishing is the process of deceiving and luring users into sharing their account details.

Advertisement

The report states hackers are using emails to target multiple sectors in the US. The emails seems to come from an “admin account” like “Rouncube Admin” or "admin@servewebteam[.]gq" and contains the subject line “Zoom Account.” The body of this mail seems to welcome users to Zoom and gives them a link to activate their account. This link takes the user to a “generic webmail landing page” where they are asked to enter their credentials.

Advertisement

Phishing email comes with subject line "Zoom Account"
Photo Credit: Proofpoint

Advertisement

 

Another phishing email discovered by Proofpoint tries to lure Zoom users with a “missed meeting” message. The mail claims that the user has missed a Zoom meeting and gives a link through which the recipient can check their missed conference. Clicking on the link takes the user to a Zoom page that looks quite official but, Proofpoint claims it is a “spoofed Zoom page.” The user is asked to enter credentials here.

Advertisement

The mail can state user has missed a Zoom meeting
Photo Credit: Proofpoint

 

A smaller campaign targeting manufacturing, industrial, marketing/advertising, technology, IT and construction companies tries to infect users with ServLoader/NetSupport remote access Trojans. The mail thanks the recipient for responding to a fake RFQ (Request for Quotation) and offers to have a Zoom call. The subject line in these mails can be “[Company] Meeting cancelled - Could we do a Zoom call”, “[Company] - I won't make it to Arizona - Could we talk over Zoom?”, “The [Company] - I won't make it to Tennessee - Can we talk over Zoom?”, and other variations.

Phishing email aims to distribute the ServLoader/NetSupport remote access Trojans
Photo Credit: Proofpoint

 

It was also found that a large agricultural firm was sent an attachment that required it to “enable macros” after which a ServLoader PowerShell script is executed and that installs NetSupport, a remote-control application.

With most of the people using video conferencing as a means of communication during the ongoing coronavirus pandemic, the threats against their privacy and security seem to be increasing. However, it should be noted that this latest threat is not Zoom's fault in particular.

 

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Zoom, Credential Phishing
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15T Details Revealed; New Telephoto Lens, Bigger Battery Confirmed
  2. Nothing Phone 4a Will Go on Sale in Bengaluru at a Drop Event on This Date
  3. Here's When the Oppo Find X9 Ultra Will Be Launched Globally
  4. iQOO 15R Goes on Sale in India Today: Know Price and Offers
  5. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  6. Apple in Talks to Run Siri on Google AI Infrastructure, Report Says
  7. Here's When the Oppo K14 5G Will Launch in India: See Expected Specs
  8. iPad Air (2026) With M4 Chip Launched in India at This Price
  9. iQOO Z11x 5G Will Launch in India on This Date
  10. Poco X8 Lineup, Poco C85x 5G Appear on Flipkart Ahead of Launch
  1. Oppo Find X9 Ultra Global Launch Confirmed; Set to Arrive Later This Year
  2. Apple Reportedly Considering Google’s Gemini Infrastructure for Advanced Siri Features
  3. Oppo K14 5G India Launch Date Announced Along With Availability, Colourways: See Expected Specs
  4. iQOO Z11x 5G India Launch Date Announced; Amazon Availability and Key Features Revealed
  5. Starfield PS5 Release Date, Pricing and Pre-Order Details Leak; Will Reportedly Launch Next Month
  6. OnePlus 15T Confirmed to Feature LUMO Periscope Telephoto Lens, Narrow Bezels
  7. Nothing Phone 4a to Go on Sale in Bengaluru at Exclusive Drop Event Days After India Launch
  8. iQOO 15R With Snapdragon 8 Gen 5 Chip Goes on Sale in India Today: Price, Offers
  9. Vivo X300 Ultra Teased With Zeiss 400mm Extender Kit at MWC 2026; Global Launch Confirmed
  10. Total Lunar Eclipse 2026: Where and How to See the Rare Blood Moon
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.