Matt Johansen @mattjay.com · Jul 3

The attacker pretends to be a trusted contact → DM on Telegram → Calendly invite → follow-up email with a Zoom link that tells victims to “run this update script.” It's been hyper successful and catching founders/devs off-guard

0 likes 1 replies

?

Replies

Matt Johansen · Jul 3

That script (`zoom_sdk_support.scpt`) hides *10,000 blank lines* scroll forever, never see the payload. The last 3 lines fetch stage-2 from `support.us05web-zoom[.]forum` (notice the look-alike Zoom domain)