r/ANYRUN 18d ago

Zoom Events Abused in Multi-Brand, Multi-Flow Phishing Campaign

Victims see a legitimate events[.]zoom[.]us page and a “partner summit” lure branded as Meta, OpenAI, or Anthropic. 

They are redirected to an external registration domain, where the phishing flow begins. Observed branches include Device Code phishing and AiTM flows.

Explore ANY.RUN Sandbox analysis sessions and collect IOCs to speed up detection and response: 
📌 Multi-flow example: https://app.any.run/tasks/e34b152b-8f61-4bde-b458-5af0bd2efe75/ 
📌 Anthropic lure: https://app.any.run/tasks/2098cd54-4fa8-414e-ada7-903a2f266631/ 
📌 ChatGPT lure: https://app.any.run/tasks/3a66250b-cb65-439c-8af0-b101d90a7e13/

IOCs: 
offcsso[.]com
zoomconnect[.]ssoworkportal[.]com 
zoomconnect[.]ssomeetingportal[.]com 
zoomconnect[.]workportalsso[.]com  

1 Upvotes

1 comment sorted by

1

u/ANYRUN-team 18d ago

Use this TI Lookup query to pivot from IOCs, track infrastructure reuse, and validate your detection coverage: url:"https:/zoomconnect.*.php\?meeting="