


It is very difficult for Secure Email Gateways (SEGs) to catch them due to the legitimacy attached to the domain names used by these threat actors. Additionally, some phishing emails also used new email domain names such as zoomcommunicationscom or zoomvideoconferencecom. The display name in the email headers shows “Zoom – This makes it appear as if it is genuinely from Zoom.Īlong with this, most of the email domains used came from legitimate but compromised accounts. Zoom Phishing Attacks Email Format (Source: Bleeping Computer) The victims receive emails saying that Zoom has undergone a server upgrade, prompting them to verify their account if they want to continue making or receiving calls through this app.
