An advanced phishing campaign impersonating Zoom meeting invitations has culminated in the theft of millions in cryptocurrency, highlighting the growing risks of cyberattacks targeting UC platforms.
As first highlighted by blockchain security firm SlowMist, the phishing campaign mimicked legitimate Zoom meeting invitations, redirecting users to a counterfeit domain, “app[.]us4zoom[.]us,” which closely imitated Zoom’s official interface.
Unlike genuine invitations that launch the Zoom client, this fraudulent site prompted users to download a malicious file disguised as “ZoomApp_v.3.14.dmg”. This fake installation package served as the attack vector, enabling cybercriminals to infiltrate systems and steal cryptocurrency.
By leveraging users' trust in widely used comms platforms, attackers have successfully deployed malware that infiltrates systems, compromising security and stealing sensitive data, including cryptocurrency wallets. This method seeks to capitalise on the familiarity and legitimacy of major platforms like Zoom to deceive users into unknowingly downloading malicious software.
More Specifics On The Hack Itself
SlowMist uncovered evidence of Russian-language scripts tracking downloads through the Telegram API, suggesting that the attackers were using this channel to monitor and manage the distribution of the malicious software. The site, deployed 27 days ago, indicates that the hackers are likely Russian. Since November 14, they have been targeting victims, utilising the Telegram API to monitor whether anyone clicked the download button on the phishing page.
Upon execution, the fake Zoom application deceived users into entering their system passwords, granting the malware elevated access to the device. The software then triggered a script named “ZoomApp.file” to run additional hidden code, ultimately activating a covert executable file labelled “.ZoomApp”.
This multi-layered process enabled the attackers to silently embed themselves deeper into the system, bypassing traditional security measures and allowing for further malicious actions such as data theft or the installation of persistent threats.
This program then collected sensitive data encompassing browser information, system data, cookies and KeyChain passwords, Telegram and Notes data, and cryptocurrency wallet keys.
The stolen data was sent to a hacker-controlled server at IP 141.98.9.20, flagged as malicious by threat platforms. Using MistTrack, SlowMist traced the hacker’s address, 0x9fd15727f43ebffd0af6fecf6e01a810348ee6ac, which accumulated over $1 million in stolen funds, including ETH, USD0++, and MORPHO. These were swapped for 296 ETH, some of which were laundered via Binance, Gate.io, and Swapspace.




