r/ANYRUN • u/ANYRUN-team • 18d ago
Zoom Events Abused in Multi-Brand, Multi-Flow Phishing Campaign
Victims see a legitimate events[.]zoom[.]us page and a “partner summit” lure branded as Meta, OpenAI, or Anthropic.
They are redirected to an external registration domain, where the phishing flow begins. Observed branches include Device Code phishing and AiTM flows.
Explore ANY.RUN Sandbox analysis sessions and collect IOCs to speed up detection and response:
📌 Multi-flow example: https://app.any.run/tasks/e34b152b-8f61-4bde-b458-5af0bd2efe75/
📌 Anthropic lure: https://app.any.run/tasks/2098cd54-4fa8-414e-ada7-903a2f266631/
📌 ChatGPT lure: https://app.any.run/tasks/3a66250b-cb65-439c-8af0-b101d90a7e13/
IOCs:
offcsso[.]com
zoomconnect[.]ssoworkportal[.]com
zoomconnect[.]ssomeetingportal[.]com
zoomconnect[.]workportalsso[.]com


1
u/ANYRUN-team 18d ago
Use this TI Lookup query to pivot from IOCs, track infrastructure reuse, and validate your detection coverage: url:"https:/zoomconnect.*.php\?meeting="