Phishing Campaign Uses Fabricated Misconduct Claims to Deliver Zoho Assist RAT

· Original article ↗

Summary

Cofense describes a phishing campaign impersonating university leaders with fabricated sexual misconduct claims. Links route victims through Google Drive to a malicious Zoho Assist download; healthcare-affiliated universities appear to be the main targets.

Key points

  • Emails spoof university presidents or deans and use fabricated sexual misconduct allegations to pressure recipients into clicking.
  • The link leads first to a Google Drive file, which then directs victims to download a malicious instance of Zoho Assist.
  • The remote access tool can provide screen control, file transfer, and the ability to deliver additional files.
  • More than 80% of the targets were healthcare-related universities, according to Cofense; the article says the campaign appears to target the public health sector.
  • The campaign uses abused cloud services and newly registered, threat actor-controlled domains to host the malware.
  • Cofense reports that the emails have bypassed some integrated cloud email security controls, even without AI-generated variations.
  • Recommended defenses include independently verifying unexpected allegations, treating software-installation requests as suspicious, and monitoring systems for compromise.

Article Details

Attack Vectors
  • Phishing emails impersonated university presidents or deans and fabricated sexual misconduct allegations to prompt recipients to click a link.
  • Emails copied university letterheads and signature blocks and spoofed university email domains.
  • The email link led to a Google Drive file containing a second link that downloaded an attacker-used Zoho Assist instance.
  • The download was hosted on abused non-Google cloud services or threat actor-controlled websites.
Defensive Notes
  • Verify purported notifications from another university through the legal department.
  • Treat a document that requires installing software as a warning sign, especially when it comes from an external sender.
  • Monitor systems for phishing attempts and remediate compromised accounts quickly.
  • Use human-vetted threat intelligence alongside automated feeds to assess whether a legitimate remote access tool is being misused.

MITRE ATT&CK

Vendors

Products

Tools

Industries

Related Articles