False Allegations, Real Threats: Sexual‑Misconduct Phishing Lures Deliver Zoho Assist RAT to University Leaders
What Happened — Threat actors are spoofing presidents and deans of U.S. universities (e.g., Notre Dame, University of Virginia, Medical College of Wisconsin) and sending emails that claim a sexual‑misconduct case. The messages contain a link to a Google Drive file that, once clicked, drops a technically legitimate Remote Access Tool – Zoho Assist – giving the attacker full control of the victim’s workstation.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous phishing‑email monitoring and rapid IOC ingestion to maintain a defensible audit trail.
- Highlights the importance of security‑awareness training and simulated phishing exercises as evidence of due‑diligence for control‑assurance programs.
- Shows that compromised endpoints can lead to regulatory non‑compliance (e.g., exposure of research data), underscoring the requirement for robust endpoint‑access controls and incident‑response evidence.
Who Is Affected – Higher‑education institutions, research labs, and any organization that collaborates with universities.
Recommended Actions
- Deploy a phishing‑email detection solution that can ingest fresh IOCs from threat‑intel feeds.
- Conduct targeted security‑awareness training that references this campaign’s social‑engineering tactics.
- Enforce MFA and least‑privilege access for remote‑access tools; log and review all remote‑session activity.
- Add Zoho Assist hash and URL indicators to endpoint detection and response (EDR) platforms.
Source: Cofense Intelligence
Technical Notes
- Attack vector: phishing email → Google Drive link → download of malicious Zoho Assist RAT.
- The RAT can view/control screens, transfer files, and act as a dropper for additional malware (including ransomware).
- No CVE is associated; the threat relies on social engineering and abuse of a legitimate remote‑access product.
Source: Cofense Intelligence