Malwarebytes reported a social-engineering campaign that uses a fake Zoom meeting lure to trick victims into installing surveillance software without obvious user awareness, highlighting continued abuse of trusted collaboration brands as an initial access vector (CSO Online). The activity fits a broader pattern of user-targeted delivery mechanisms—such as SEO poisoning/malvertising that pushes trojanized admin tools (e.g., PuTTY/WinSCP) and known loaders like Oyster/CleanUpLoader—to compromise software professionals and business users via seemingly legitimate download paths.
Several other items in the set are not about this incident and should be treated as off-topic or low-signal for incident tracking: a policy/politics discussion about US DoD pressure on Anthropic’s Claude for military use, a detection-engineering newsletter that includes hiring and a webinar plug, a CSIS roll-up page listing historical “significant cyber incidents,” and a Dark Reading piece focused on cybersecurity VC/M&A trends tied to AI. Those sources do not provide corroborating details, IOCs, or technical specifics about the fake-Zoom surveillance campaign itself.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf reported a BlueNoroff campaign targeting Web3, cryptocurrency, and finance-related organizations through fake Zoom and Microsoft Teams meeting lures, including fraudulent Calendly invites and deepfake impersonation. Victims were tricked into pasting a malicious PowerShell command into a terminal, leading to fileless persistence and theft of browser data, credentials, Telegram sessions, and cryptocurrency wallet keys; the campaign reportedly hit more than 100 targets in over 20 countries.
Breakglass Intelligence published a technical analysis tying more than 38 FakeMeeting phishing domains impersonating Google Meet, Zoom, DocuSign, and Paperless Post to Loominost-hosted infrastructure on Shock Hosting. The report identified attribution and detection pivots including the SOA email johnseamus89@gmail.com, WHOIS name 'Terry Johnson,' shared Google Analytics ID G-XDVX0QEYVC, Loominost nameservers, and infrastructure associated with delivery of Teramind via fake meeting-update lures.
CISA added FileZen vulnerability CVE-2026-25108, an OS command injection flaw, to its Known Exploited Vulnerabilities catalog after active exploitation was observed. The issue was described with a CVSS v4 score of 8.7.
A GitHub Codespaces vulnerability dubbed 'RoguePilot' was responsibly disclosed to Microsoft and then patched. The flaw could have enabled repository takeover by injecting malicious Copilot instructions into AI-assisted development workflows.
Malwarebytes reported a social-engineering campaign in which a fake Zoom meeting silently installed surveillance software on victims' systems. The CSO reference highlights the campaign as a current security news item.
VMware remediated a command injection flaw affecting Aria Operations. The CSO item notes the vulnerability had been fixed, though it does not provide further technical detail.
SolarWinds issued updates for four critical vulnerabilities in Serv-U 15.5, each described as high-impact and potentially enabling remote code execution. The digest characterizes the flaws as critical with CVSS scores up to 9.1.
Palo Alto Networks Unit 42 reported on Lazarus-linked campaigns known as Contagious Interview and Wagemole, which used fake job-interview lures and fraudulent employment activity to target software developers and U.S. companies. The report described BeaverTail and InvisibleFerret malware capabilities and published associated sample hashes and technical indicators.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 108 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourceintel.breakglass.tech
Open sourcecloudatg.com
Open sourcecsoonline.com
Open sourcecontagiodump.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.