Mitigating ELUSIVE COMET Zoom remote control attacks
2025-04-17 • Trailofbits •
https://blog.trailofbits.com/2025/04/17/mitigating-elusive-comet-zoom-remote-control-attacks/
Trail of Bits describes an ELUSIVE COMET social-engineering attempt that invited its CEO to a fake "Bloomberg Crypto" appearance through suspicious Twitter accounts and non-Bloomberg Calendly pages. The campaign targets cryptocurrency and security professionals by creating a legitimate-looking business call, then abusing Zoom's remote-control feature after the victim starts screen sharing. Attackers can rename themselves "Zoom" so the request resembles a system prompt; if approved, they may install malware, exfiltrate data, or steal cryptocurrency. Trail of Bits published new indicators including [email protected], a Zoom meeting URL, and Calendly pages for bloombergseries and cryptobloomberg, and recommends disabling Zoom remote control where it is not needed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |
| DOMAIN | g00gle.com | 2025-04-17 | 2025-04-17 |