Security Stop-Press: Hackers Exploit Zoom Remote Control to Hijack Devices

Written by Pronetic

Pronetic is a leading provider of core IT support for ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance.

April 30, 2025

A new cyber campaign is exploiting Zoom’s remote control feature to install malware, exfiltrate data, and hijack victim devices, researchers have warned.

The attack, linked to a threat group called Elusive Comet, tricks users into granting remote access during fake Zoom interviews arranged via bogus Calendly links and spoofed Bloomberg emails. Once on the call, attackers rename themselves “Zoom” to make their remote control request look like a harmless system notification.

Trail of Bits, who uncovered the attack, warned that “users habituated to clicking ‘Approve’ on Zoom prompts may grant complete control of their computer without realising the implications.” This method bypasses technical vulnerabilities and instead relies on exploiting normal user behaviour and trust in legitimate platforms.

Security experts say the incident highlights the growing threat of ‘living off trusted services’ (LOTS) attacks, with Mimecast noting over five billion such threats were flagged in late 2024 alone. Using Zoom and Calendly links makes these attacks harder to detect and block.

Businesses can protect themselves by blocking Zoom’s remote control permissions, encouraging browser-based meeting tools like Google Meet, hardening authentication with security keys, and training staff to spot suspicious activity during video calls.

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Why Choose Pronetic

We Are ISO 27001 & Cyber Essentials Plus Certified

Be reassured that we have been externally audited. You can have complete peace of mind that the team managing your IT systems and safeguarding your data are independently vetted annually.

Seamless & Comprehensive IT Support

Our investment in people, tools and processes, continuously improved, ensures that we don’t just deliver exceptional I.T. support but include your compliance to Cyber Essentials or ISO 27001 “baked-in”. Yes, that means no more annual headaches and stress when your certification comes round.

Expert Support Money Back Guarantee

We're confident in the value we deliver. That's why we offer a 90-day, no-quibble money-back guarantee. If, for any reason, you're not completely satisfied with our IT support services, we'll provide a full refund and cancel your contract without any hassle.

Book Your Free IT Strategy Call Now!

Simply Fill In The Form Below To Receive Your Free IT Strategy Call:

By submitting this form, you consent to us using your personal information to contact you. For more information please see our privacy policy.