MeetingTV has sued Palo Alto Networks, Koi Security, and named Koi researchers over a threat-intelligence report that allegedly falsely tied the startup and its Zoomcorder product to a China-linked espionage and malware operation identified as Dark Spectre. According to the complaint, Koi used an AI-driven analysis platform called Wings to produce unsupported or fabricated findings, including references to an alleged browser extension, and published the report without first seeking verification from MeetingTV. Palo Alto Networks said it is aware of the lawsuit and expects the matter to be resolved through the legal process.
The startup alleges the report caused immediate operational harm after security vendors and service providers reportedly classified its domains and services as malware or command-and-control infrastructure, leading to blocking and disruption. The suit also claims the report was issued while Koi was negotiating its reported $400 million acquisition by Palo Alto Networks, alleging the publication helped boost Koi’s valuation and generate sales leads. References to MeetingTV and Zoomcorder were later removed from the original Koi blog post.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
MeetingTV filed a lawsuit against Palo Alto Networks, Koi Security, and named Koi researchers over the report, alleging false links to Chinese espionage and AI-hallucinated findings. Palo Alto Networks said it was aware of the lawsuit and expected the dispute to be resolved through legal process.
Palo Alto Networks or Koi later updated the original blog/report to remove references to MeetingTV and its Zoomcorder product. This change occurred after the disputed claims had been published.
After the report's publication, MeetingTV said multiple security vendors and service providers blocked or blacklisted its domains and services as malware or command-and-control infrastructure. The company said this disrupted its operations and caused harm.
In December, Koi Security published a threat-intelligence report that allegedly linked MeetingTV and its Zoomcorder product to the China-linked threat actor Dark Spectre and related espionage activity. MeetingTV later alleged the report relied on unverified AI-generated analysis from Koi's Wings platform and included fabricated or unsupported findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.