Hacker News new | ask | show | jobs
Look mom HR application, look mom no job – phishing using Zoom docs (blog.himanshuanand.com)
1 points by unknownhad 249 days ago
1 comments

A phishing campaign that uses Zoom's document share flow as the initial trust vector.

It forces victims through a fake "bot protection" gate, then shows a Gmail-like login. When someone types credentials, they are pushed out to the attacker over a WebSocket and the backend validates them.