• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Proofpoint Warns Middle East Users Against Threats On Video Services

by CXO Staff
April 26, 2020
in News

Proofpoint researchers have observed an increase in video conferencing company-themed attacks seeking to steal credentials and distribute malware

cybersecurity digital defence cybersecurity risk DDoS

Proofpoint researchers have observed an increase in video conferencing company-themed attacks seeking to steal credentials and distribute malware since March 27, 2020. These lures capitalise on the global workforce’s shift to remote work and consequential increased demand for video conferencing services during the COVID-19 pandemic.

To note, these attacks do not leverage or attack video conferencing software directly, said researchers from Proofpoint. Threat actors are using the names and brands of these video conferencing companies as themes in their social engineering lures, which lead to the theft of various account credentials, malware distribution, or credential harvesting for these spoofed video conferencing accounts.

“Video conferencing has become very popular very quickly, in the Middle East, as well as globally. Attackers have noticed and moved to capitalise on that popularity and brand strength,” said Emile Abou Saleh, Regional Director, Middle East & Africa at Proofpoint.

According to Saleh, not only are attackers using video conferencing brands as a lure for malware, but they’re using it for credential phishing, in particular to steal Zoom and WebEx credentials.

“This points to the increasing value of compromised video conferencing accounts. Stolen account credentials could be used to login to corporate video conferencing accounts and violate confidentiality. They also could likely be sold on the black market or used to gain further information about potential targets for launching additional attacks,” said Saleh from Proofpoint.

The emails you need to look out for

Credential Phish: Zoom Account

 This medium-sized campaign has targeted energy, manufacturing, and business services in the US and is designed to steal user credentials. The message body includes a lure that claims to welcome users to their new Zoom account.

fig 1 proofpoint

Figure 1 – False Zoom Activation Lure

Emails in this campaign arrive with a subject line of “Zoom Account” and purport to be from an admin account. In the sample in Figure 1, the message claims to come from “Rouncube Admin”. Other email lures claim to be from “admin@servewebteam[.]gq”.

 The message body includes a lure that welcomes users to their new Zoom account and contains a link, which the recipient is urged to click in order to activate their Zoom account. When clicked, users are taken to a generic webmail landing page and asked to enter their credentials.

 Credential Phish: Missed Zoom Meeting

 This small campaign targets transportation, manufacturing, technology, business services, and aerospace companies in the US and seeks to steal user credentials using a lure around a missed meeting. The emails arrive claiming that the recipient missed a Zoom meeting and includes a link the recipient can use to “Check your missed conference”.

If the recipient clicks on the link, they are taken to a spoofed Zoom page and asked for their Zoom credentials.

 Credential Phish: Cisco WebEx “Alert!” “Your account access will be limited!”

This small campaign attempted to harvest WebEx users’ credentials with emails claiming that recipients need to take immediate action to address a WebEx security vulnerability. Industries targeted include technology, accounting, aerospace, energy, healthcare, telecommunications, transportation, government, and manufacturing companies.

 

picture 2

Figure 2 – Lure with Spoofed Cisco WebEx Branding Claiming Critical Vulnerability

This campaign claims to come from addresses such as “cisco@webex[.]com” or “meetings@webex[.]com”  and uses subject lines such as: “Critical Update!” , “Alert!”, “Critical Update!”, “Your account access will be limited!” or “Your account access will be limited in 24h.”

The emails claim that the recipient needs to update their WebEx client to “fix” a security vulnerability in the Docker Engine Configuration in Cisco CloudCenter Orchestrator. The messages very prominently abuse the Cisco WebEx logo and spoof the format of Cisco’s security advisories. They also appear to draw text and images from a legitimate Cisco advisory. If the recipient clicks on the link, they are taken to the page which asks for the user’s WebEx credentials.

fig 3

Figure 3 –  WebEx Credential Phishing Page

As video teleconferencing has become more important than ever to the global workforce, it’s not surprising that attackers are moving to adapt their themes and lures to include prominent video conferencing providers like WebEx and Zoom. With more and more organisations shifting to remote work, we can expect these video teleconferencing brands to continue to be used as themes in social engineering lures for the foreseeable future.

 

Tags: credentialsEmile Abou Salehfeatured1malwareProofpointSecurityWebexZoom
ShareTweet

Related Posts

Apple unveils elegant new software design
Future

Apple unveils elegant new software design

Apple has unveiled its most comprehensive software design update to date, debuting an elegant new interface across all its platforms,...

June 10, 2025
Kissflow targets growth in Germany with new AI features
Business

Kissflow targets growth in Germany with new AI features

Kissflow announced its strategic expansion in Germany, identifying it as a key market in its global growth roadmap. With the...

June 10, 2025

Discussion about this post

Latest Issue

Apple unveils elegant new software design

Apple unveils elegant new software design

June 10, 2025
Kissflow targets growth in Germany with new AI features

Kissflow targets growth in Germany with new AI features

June 10, 2025
Redington and Autodesk chart new territories through expanded alliance

Redington and Autodesk chart new territories through expanded alliance

June 10, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.