Security researchers are raising the alarm about a sophisticated phishing campaign that has successfully targeted more than 900 organizations by gaining access through Zoom and Microsoft Teams.
Cybersecurity company Abnormal has uncovered a new trend in which attackers are abandoning traditional password theft in favor of tricking employees into voluntarily installing spyware.
By mimicking authentic-looking UC meeting invitations and leveraging compromised email threads, criminals are able to slip past even the most vigilant security teams without raising the alarm.
With this threat increasingly deceiving businesses, how can organizations and individuals protect themselves and their UC usage from this emerging risk?
The Anatomy of a Modern Workplace Deception
The sophistication of this campaign sets it apart from conventional phishing attempts.
Instead of relying on obviously suspicious emails or crude impersonation tactics, these attackers have industrialized their strategies through dark web marketplaces that sell complete "attack kits" for ConnectWise ScreenConnect—a legitimate IT administration tool that can become a powerful weapon in the wrong hands.
By using real file-sharing platforms and AI-generated phishing pages, along with compromised email accounts and conversation threads, attackers create a network of correspondence that is harder to distinguish from legitimate communications.
Once a victim is tricked into installing ConnectWise ScreenConnect, attackers lure individuals into granting them administrator-level access to corporate systems. After entry, they launch account takeovers, lateral phishing campaigns, and data theft while blending in with normal IT activity.
The geographic distribution of victims—primarily in the US, UK, Canada, and Australia—suggests these are not opportunistic attacks but meticulously planned campaigns targeting English-speaking markets with high rates of remote work adoption.
The sectoral targeting of education (14.4% of victims), healthcare (9.7%), and financial services (9.4%) indicates attackers understand which industries are most susceptible to disruption and possess valuable data for theft or ransom.
Building Resilience Against Social Engineering
Protection against these advanced attacks requires a multi-layered approach addressing both technological vulnerabilities and human psychology.




