Phishing Attack Pretends to Be Zoom Invites to Harvest Login Credentials

Phishing Attack Pretends to Be Zoom Invites to Harvest Login Credentials

A new and highly advanced phishing scheme has emerged, taking advantage of the widespread use of Zoom by corporate users. This attack uses fake meeting invitations that are designed to look like they’ve come from trusted colleagues.

By employing clever social engineering strategies, the phishing emails create a false sense of urgency, pushing recipients to click on links that appear legitimate but are actually malicious.

Once clicked, these links lead victims through a deceptive process designed to steal their Zoom login credentials. The phishing emails are carefully crafted to resemble authentic Zoom meeting notifications, with familiar branding, structure, and language that suggest an immediate action is required.

Subject lines like “Missed Zoom Call” or “Urgent Meeting Request” are used to provoke quick, impulsive reactions from professionals who are already overwhelmed with multiple messages and tasks during their workday.

When a victim clicks the fraudulent link, they are taken to a convincing duplicate of the Zoom interface, which shows what appears to be a video call with colleagues waiting. This trickery creates a false sense of a live meeting in progress, pushing victims to join without further thought.

The campaign, first discovered on May 19, 2025, was flagged by SpiderLabs researchers, who noted its enhanced impact due to the use of pre-recorded video content that simulates an actual meeting scenario.

“This attack marks a new phase in phishing evolution, utilizing dynamic visuals to bypass user doubt,” the security team explained in their advisory.

The attack follows a well-crafted five-stage process. After receiving the phishing email, victims who click the malicious link are shown a fake loading screen, which mimics Zoom’s authentic interface, drawing them further into the scam.

Attack Progression (Source – X)

The page seamlessly transitions to show a pre-recorded video featuring “participants” in a meeting, cleverly simulating the feel of an active video call.

Shortly after, users are presented with a deceptive disconnection alert, followed by a counterfeit login prompt intended to capture their login credentials.

The attack infrastructure operates across various domains, with initial tracking conducted through subdomains associated with cirrusinsight.com, and meeting pages hosted on r2.dev services.

An investigation into the network traffic reveals that stolen credentials are sent via Telegram API endpoints, enabling attackers to collect data in real-time. This method also ensures they maintain operational security by using commonly accepted communication channels, which often evade standard security measures.

More Articles & Posts