Phishing Campaign Uses Fabricated Misconduct Claims to Deliver Zoho Assist RAT

Summary
Cofense describes a phishing campaign impersonating university leaders with fabricated sexual misconduct claims. Links route victims through Google Drive to a malicious Zoho Assist download; healthcare-affiliated universities appear to be the main targets.
Key points
- Emails spoof university presidents or deans and use fabricated sexual misconduct allegations to pressure recipients into clicking.
- The link leads first to a Google Drive file, which then directs victims to download a malicious instance of Zoho Assist.
- The remote access tool can provide screen control, file transfer, and the ability to deliver additional files.
- More than 80% of the targets were healthcare-related universities, according to Cofense; the article says the campaign appears to target the public health sector.
- The campaign uses abused cloud services and newly registered, threat actor-controlled domains to host the malware.
- Cofense reports that the emails have bypassed some integrated cloud email security controls, even without AI-generated variations.
- Recommended defenses include independently verifying unexpected allegations, treating software-installation requests as suspicious, and monitoring systems for compromise.
Article Details
- Attack Vectors
- Phishing emails impersonated university presidents or deans and fabricated sexual misconduct allegations to prompt recipients to click a link.
- Emails copied university letterheads and signature blocks and spoofed university email domains.
- The email link led to a Google Drive file containing a second link that downloaded an attacker-used Zoho Assist instance.
- The download was hosted on abused non-Google cloud services or threat actor-controlled websites.
- Defensive Notes
- Verify purported notifications from another university through the legal department.
- Treat a document that requires installing software as a warning sign, especially when it comes from an external sender.
- Monitor systems for phishing attempts and remediate compromised accounts quickly.
- Use human-vetted threat intelligence alongside automated feeds to assess whether a legitimate remote access tool is being misused.
MITRE ATT&CK
T1105 · Ingress Tool TransferClicking the link in the Google Drive file downloaded the attacker-used Zoho Assist instance to the recipient’s computer.T1219 · Remote Access ToolsThe campaign induced recipients to install an attacker-used instance of the legitimate remote access product Zoho Assist.T1566.002 · Spearphishing LinkEmails alleging sexual misconduct directed recipients to a Google Drive link that led to a download link.
Vendors
Googleare in a rush or multitasking. If the email recipient clicks the phishing email link, they are sent to a Google Drive file first. This first URL helps obfuscate malware from the email security technologies. The GoogleZohothe Medical College of Wisconsin. Instead of a document file, an abused, technically legitimate RAT called Zoho Assist is downloaded to the victim’s computer.
Products
Google Drivein a rush or multitasking. If the email recipient clicks the phishing email link, they are sent to a Google Drive file first. This first URL helps obfuscate malware from the email security technologies. The GoogleZoho AssistMedical College of Wisconsin. Instead of a document file, an abused, technically legitimate RAT called Zoho Assist is downloaded to the victim’s computer.
Tools
Cofense Triagesystems to catch phishing attempts early and remediate compromised accounts quickly. Tools such as Cofense Triage and Vision give security teams the visibility needed to act before an account is fully compromised.Visionphishing attempts early and remediate compromised accounts quickly. Tools such as Cofense Triage and Vision give security teams the visibility needed to act before an account is fully compromised.
Industries
HealthcareThe bulk of the phishing attempts appear to be against health care industry-affiliated universities. This makes it likely that threat actors intentionally targeted these organizations. This is concerning because Publicpublic healthPublic health is especially important given that it is one of 16 sectors designated by CISA as critical infrastructure.