---
title: Prolific Phishing Campaign Leveraging Zoom's Infrastructure
description: Phishing campaign exploits Zoom Events infrastructure to deliver credential phishing and malicious downloads, bypassing email security filters. Learn how to protect your organization.
image: https://blog.reconinfosec.com/hubfs/SSA_phish_email.png
---

[Skip to content](https://blog.reconinfosec.com/zoom-events-phishing#main-content)

[![recon_infosec.png](https://blog.reconinfosec.com/hs-fs/hubfs/recon-logo-full-on-white.png?width=7680&height=2304&name=recon-logo-full-on-white.png "recon_infosec.png")](http://reconinfosec.com)

- [Website Home](https://www.reconinfosec.com/)

- [Website Home](https://www.reconinfosec.com/)

# Prolific Phishing Campaign Leveraging Zoom's Infrastructure

[Michael Robertson](https://blog.reconinfosec.com/author/michael-robertson)

The Recon SOC recently identified a significant uptick in phishing campaigns that exploit the legitimate infrastructure of Zoom Events.

These phishing attempts originate from noreply-zoomevents@zoom.us, bypassing numerous email security filters. These messages are cryptographically signed (SPF/DKIM/DMARC) and originate from Zoom Events, making it exceedingly difficult for users to identify them as phishing.

Headers from an example email we’ve observed show the following authentication information:

“[Pass (protection.outlook.com: domain of bounce-sg.zoom.us designates 159.183.192.104 as permitted sender)](https://www.abuseipdb.com/check/159.183.192.104); helo=o26.sg.zoom.us; pr=C”

“[spf=pass (sender IP is 159.183.192.104)](https://www.abuseipdb.com/check/159.183.192.104) [smtp.mailfrom=bounce-sg.zoom.us](https://www.spf-record.com/spf-lookup/bounce-sg.zoom.us); dkim=pass (signature was verified) header.d=zoom.us;dmarc=pass action=none header.from=zoom.us;compauth=pass reason=100”

[![abuseipdb](https://blog.reconinfosec.com/hs-fs/hubfs/abuseipdb.png?width=320&height=275&name=abuseipdb.png)](https://www.google.com/url?q=https://www.abuseipdb.com/check/159.183.192.104&sa=D&source=docs&ust=1750458579471377&usg=AOvVaw1jFn_Nk7ysbI8LvrXWRWOw)                  [![spf_record](https://blog.reconinfosec.com/hs-fs/hubfs/spf_record.png?width=563&height=196&name=spf_record.png)](https://www.spf-record.com/spf-lookup/bounce-sg.zoom.us)

We have observed both credential phishing and malicious desktop applications, urging users to “View file” and “Download Desktop App Now”. In all cases, there was an initial link to `hxxps://docs.zoom.us/doc/`. From there, users were either redirected to an AitM credential phishing site, or a malicious ScreenConnect\[.\]exe download. 

This is [not an entirely new technique for AitM phishing](https://cofense.com/blog/from-collaboration-to-deception-the-zoom-phishing-threat)using `hxxps://docs.zoom.us/doc/.` However, unlike previously reported campaigns, this latest threat includes the abuse of Zoom Events.

# Credential Phishing Using Zoom Events

The credential phishing emails utilize ChainLink Phishing, calling users to open a link to a document/file, leading to `hxxps://docs.zoom.us/doc/`, directing them to click to another link that displays a fake verification request (CAPTCHA), then to an AitM Microsoft login page where they are prompted to enter their credentials.

Example Malicious Email:

![phish_email_excel](https://blog.reconinfosec.com/hs-fs/hubfs/phish_email_excel.png?width=520&height=295&name=phish_email_excel.png)

Sample hxxps\[://\]docs\[.\]zoom\[.\]us/doc/ page:

![phish_page_office_icons](https://blog.reconinfosec.com/hs-fs/hubfs/phish_email_office_icons.png?width=427&height=392&name=phish_email_office_icons.png)

Fake verification page:

![Screenshot 2025-06-20 at 5.32.57 PM](https://blog.reconinfosec.com/hs-fs/hubfs/Screenshot%202025-06-20%20at%205.32.57%20PM.png?width=305&height=110&name=Screenshot%202025-06-20%20at%205.32.57%20PM.png)![Screenshot 2025-06-20 at 5.33.56 PM](https://blog.reconinfosec.com/hs-fs/hubfs/Screenshot%202025-06-20%20at%205.33.56%20PM.png?width=362&height=119&name=Screenshot%202025-06-20%20at%205.33.56%20PM.png)

Phishing landing page:

![Screenshot 2025-06-20 at 5.54.57 PM](https://blog.reconinfosec.com/hs-fs/hubfs/Screenshot%202025-06-20%20at%205.54.57%20PM.png?width=542&height=398&name=Screenshot%202025-06-20%20at%205.54.57%20PM.png)

## Delivering Malicious Downloads Using Zoom Events

The malicious download phishing emails utilize ChainLink Phishing, calling users to open a link to a document/file, leading to `hxxps://docs.zoom.us/doc/`, then to a malicious download. It appears that the same email is sent to multiple users across different organizations, all with the same `docs.zoom.us` link.

At one point during our investigation, for a new email, we found that several users were accessing the shared Zoom doc at the same time.

Example Malicious Email:

![SSA_phish_email](https://blog.reconinfosec.com/hs-fs/hubfs/SSA_phish_email.png?width=503&height=619&name=SSA_phish_email.png)

hxxps://docs.zoom.us/doc/ page:

![SSA_phish_page](https://blog.reconinfosec.com/hs-fs/hubfs/SSA_phish_page.png?width=624&height=643&name=SSA_phish_page.png)

This sample is now even more concerning, as it’s downloading a malware payload - which we’ve identified as [a renamed ScreenConnect binary](https://www.joesandbox.com/analysis/1719604).

App Protection Warning on Fake ScreenConnect Binary:

**![renamed_binary](https://blog.reconinfosec.com/hs-fs/hubfs/renamed_binary.png?width=480&height=433&name=renamed_binary.png)**

There are other recently uploaded examples with similar file names and similar `docs.zoom.us`links, most likely attributed to this same campaign, [that we found on ANY.RUN](https://any.run/report/e5b225b87906e355a42a6fec46601586257840fc0c35a8fcc2b4d8e7cec23fa8/4375f143-b9cc-42c0-a4a3-6cd8a69e694e).

Customers protected by [Sublime](https://sublime.security/) and Recon's Advanced Email Protection (AEP) offering will find these messages automatically quarantined. Recon's engineers started crafting the necessary detection rules to identify these threats within hours of their initial discovery.

[Sublime](https://sublime.security/) MQL Detection Logic:

![detections](https://blog.reconinfosec.com/hs-fs/hubfs/detections.png?width=624&height=344&name=detections.png)

We submitted a case to Zoom on Thursday evening, alerting them of the fraudulent activity sent from their platform, and offering samples. Our case was closed, saying that enforcing DMARC prevents this, despite our observation of DMARC passing. Friday afternoon, we opened another case and submitted samples. It appears that these attackers are leveraging compromised user accounts with access to “[Zoom Events Email Builder](https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0057915)”.

## Key Indicators of this phishing campaign:

- **Deceptive Subject Lines & Content:** These have been seen mimicking urgent financial, file sharing, or government notices.
- **Impersonation:** This campaign impersonates legitimate organizations such as the Social Security Administration and investment firms.
- **Call to Action:** Recipients are pressured to download desktop applications or click "View File" buttons within the email.
- **Misleading Branding:** Emails feature Microsoft Office icons or Zoom Events footers with deceptive instructions to act on a "secure" document.
- **Malicious Links:** Links typically redirect to credential harvesting sites or attempt to download malicious renamed ScreenConnect executables.

## Protect your organization:

- Users should be **warned not to click on links or download files** from unexpected "Zoom Events" emails.
- If a message appears suspicious, **verify its legitimacy with the sender through an independent channel** rather than by directly replying.
- **Report any suspicious emails** using your organization's established user-reported email systems.

## IOCs:

AitM Phishing URLs:  
`hxxps[://]office[.]regencyoutdor[.]com/JUinaeSo`  
`hxxps[://]od9[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]ffdsjf9[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]call[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]0ffgyedfrvl[.]qkipikpp[.]es/H7mozVCPB@35vHfGN`  
`hxxps[://]foiufl[.]qkipikpp[.]es/H7mozVCPB@35vHfGN`  
`hxxps[://]dnffeerof9[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]rrof9[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]scjool[.]qkipikpp[.]es/H7mozVCPB@35vHfGN`  
`hxxps[://]trtiro[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]79ml2xl73[.]gwzimifoi[.]es/mxci!oD9ymNViz1JTv/`  
`hxxps[://]looil[.]qkipikpp[.]es/H7mozVCPB@35vHfGN`  
`hxxps[://]swiftde[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]truiro[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]sso[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]tuiriro[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]invest[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]pgjonesadr[.]com/js`  
`hxxps[://]yuide[.]qkipikpp[.]es/PFsfkU!WQgMbZ/`  
`hxxps[://]spsol[.]qkipikpp[.]es/H7mozVCPB@35vHfGN`

Renamed Screenconnect Malicious payload URL:  
`hxxps[://]okekeimmigrationlawyer[.]com/js/`  
`https://www.joesandbox.com/analysis/1719604`

 

 

[Follow us on LinkedIn](https://www.linkedin.com/company/recon-infosec/) [Follow us on Twitter](https://twitter.com/Recon_InfoSec) [Join us on Discord](https://reconis.co/discord) [Follow us on Mastodon](https://infosec.exchange/@recon_infosec) [Follow us on Bluesky](https://bsky.app/profile/reconinfosec.com)

[SecOps](https://blog.reconinfosec.com/tag/secops), [Intel](https://blog.reconinfosec.com/tag/intel), [phishing](https://blog.reconinfosec.com/tag/phishing), [fraud](https://blog.reconinfosec.com/tag/fraud), [Email Security](https://blog.reconinfosec.com/tag/email-security)

## Read On

[![](https://lh6.googleusercontent.com/hKOE9u5jsUy-4JOw2Z2G_bFbZwfiawpLKNXax-T97fJYEh55vg29TV0qxQHRULQqj_9_MqwQVMBgoCtk1iAJGVz1XKzbA_qvujidS1XdJ5zPZnbSWqpXJE0TiFn2wZ1-Q1dsqCXDjQ)](https://blog.reconinfosec.com/phishing-campaign)

### [Widespread Phishing and Business Email Compromise Campaign](https://blog.reconinfosec.com/phishing-campaign)

In this blog post we cover a widespread phishing campaign Recon recently observed targeting...

[![](https://blog.reconinfosec.com/hs-fs/hubfs/image-png-May-10-2023-07-09-43-2952-AM.png?width=352&name=image-png-May-10-2023-07-09-43-2952-AM.png)](https://blog.reconinfosec.com/emergence-of-akira-ransomware-group)

### [Emergence of Akira Ransomware Group](https://blog.reconinfosec.com/emergence-of-akira-ransomware-group)

The Recon SOC recently worked an IR case involving the newly emerged Akira Ransomware Group. News...

### [Every Organization Needs Centralized Logging](https://blog.reconinfosec.com/every-organization-needs-centralized-logging)

### **Logs are on the systems, why do I need this?**

**Because Digital Forensics & Incident Response is...**

© 2026 All rights reserved. [RSS Feed](https://blog.reconinfosec.com/rss.xml)