top | item 45517569

Look mom HR application, look mom no job – phishing using Zoom docs

1 points| unknownhad | 4 months ago |blog.himanshuanand.com

1 comment

order

unknownhad|4 months ago

A phishing campaign that uses Zoom's document share flow as the initial trust vector.

It forces victims through a fake "bot protection" gate, then shows a Gmail-like login. When someone types credentials, they are pushed out to the attacker over a WebSocket and the backend validates them.