HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Phishing Campaign Uses Fabricated Sexual Misconduct Allegations to Deploy Zoho Assist RAT to University Leaders

Threat actors spoof university presidents and deans, claiming a sexual‑misconduct case to trick recipients into downloading the Zoho Assist remote‑access tool. The campaign shows why continuous phishing monitoring, security‑awareness training, and endpoint‑access controls are essential for audit‑ready control assurance.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 cofense.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cofense.com

False Allegations, Real Threats: Sexual‑Misconduct Phishing Lures Deliver Zoho Assist RAT to University Leaders

What Happened — Threat actors are spoofing presidents and deans of U.S. universities (e.g., Notre Dame, University of Virginia, Medical College of Wisconsin) and sending emails that claim a sexual‑misconduct case. The messages contain a link to a Google Drive file that, once clicked, drops a technically legitimate Remote Access Tool – Zoho Assist – giving the attacker full control of the victim’s workstation.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous phishing‑email monitoring and rapid IOC ingestion to maintain a defensible audit trail.
  • Highlights the importance of security‑awareness training and simulated phishing exercises as evidence of due‑diligence for control‑assurance programs.
  • Shows that compromised endpoints can lead to regulatory non‑compliance (e.g., exposure of research data), underscoring the requirement for robust endpoint‑access controls and incident‑response evidence.

Who Is Affected – Higher‑education institutions, research labs, and any organization that collaborates with universities.

Recommended Actions

  • Deploy a phishing‑email detection solution that can ingest fresh IOCs from threat‑intel feeds.
  • Conduct targeted security‑awareness training that references this campaign’s social‑engineering tactics.
  • Enforce MFA and least‑privilege access for remote‑access tools; log and review all remote‑session activity.
  • Add Zoho Assist hash and URL indicators to endpoint detection and response (EDR) platforms.

Source: Cofense Intelligence

Technical Notes

  • Attack vector: phishing email → Google Drive link → download of malicious Zoho Assist RAT.
  • The RAT can view/control screens, transfer files, and act as a dropper for additional malware (including ransomware).
  • No CVE is associated; the threat relies on social engineering and abuse of a legitimate remote‑access product.

Source: Cofense Intelligence

📰 Original Source
https://cofense.com/blog/false-allegations,-real-threats-sexual-misconduct-claims-used-as-phishing-lures

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →