By Balaji N September 20, 2022
When Cyble Research and Intelligence Labs (CRIL) was carrying out routine threat hunting exercises, it came across a tweet that mentioned numerous fake Zoom sites being created, which caught the attention of the researchers.
There is a lot of similarity in the user interfaces of these sites. The purpose of these sites is to infect people with malware disguised as Zoom’s legitimate application, using this site as a vehicle for spreading malware.
After conducting further investigation, the cybersecurity analysts found that Vidar Stealer was being spread on these sites. Vidar is a malicious program that steals information from its victims including the following data:-