Back to News
general🌐InternationalBleepingComputer

Zoom Stealer browser extensions harvest corporate meeting intelligence

Tuesday, December 30, 2025

Zoom Stealer browser extensions harvest corporate meeting intelligence

What

The DarkSpectre APT group is deploying Zoom Stealer browser extensions to collect sensitive corporate meeting data from 2.2 million users across major browsers. This campaign enables corporate espionage, social engineering, and potential sale of confidential meeting access, posing a significant threat to organizational security.

Where

Primarily Chrome, Firefox, and Microsoft Edge users globally, impacting individuals and organizations utilizing 28 video-conferencing platforms like Zoom, Microsoft Teams, and Google Meet.

When

Discovered and reported on December 30, 2025.

Key Factors

  • The DarkSpectre APT group, linked to China, leverages 18 functional but malicious browser extensions, including Chrome Audio Capture, to exfiltrate sensitive meeting data from 2.2 million users.
  • The extensions target 28 video-conferencing platforms, collecting meeting URLs, IDs, embedded passwords, speaker details, and company metadata in real-time via WebSocket connections.
  • Attribution to China is strengthened by Alibaba Cloud hosting, ICP registrations, Chinese code artifacts, and activity patterns matching the Chinese timezone.

Takeaways

  • Users should immediately review and limit browser extension permissions to the absolute minimum required, removing any suspicious or unnecessary extensions, especially those requesting broad access to web content.
  • Organizations must implement strict policies regarding browser extension usage, conduct regular audits of installed extensions, and educate employees on the risks of installing unverified software.
Read Full Article

Opens original article on BleepingComputer

Similar News