Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Zoom Infrastructure Abused in New TOAD Phishing Campaign Bypassing Email Security Controls

ChatGPT Image 30.01.2026 г., 10_04_28

Zoom Infrastructure Abused in New TOAD Phishing Campaign Bypassing Email Security Controls

A newly observed phishing campaign demonstrates how attackers are increasingly abusing legitimate SaaS infrastructure to bypass traditional email security controls. The campaign leverages Zoom’s own authentication emails as part of a Telephone-Oriented Attack Delivery (TOAD) technique, allowing social engineering payloads to reach victims through fully authenticated messages.

Unlike classic phishing attempts that rely on spoofed domains or malicious links, this attack uses Zoom’s official email systems, causing the messages to pass SPF, DKIM, and DMARC checks and evade Secure Email Gateways that trust verified senders.

How the Attack Works

The attack chain is simple, quiet, and effective:

  1. Account creation
    The attacker registers a legitimate Zoom account using an email address they control.
  2. Payload placement in display name
    Instead of a normal account name, the attacker inserts a fraudulent message into the Zoom account’s display name, such as a fake payment alert combined with a phone number.
  3. Triggering a legitimate OTP email
    A standard Zoom login attempt triggers an official One-Time Password email from Zoom’s infrastructure.
  4. Phishing delivery
    The victim receives an authentic Zoom email where the display name is rendered as part of the email body, exposing the social engineering message.

No malicious links. No attachments. No spoofing. The email itself is technically clean. The payload exists entirely within trusted content.

Why Traditional Controls Fail

This campaign highlights a growing blind spot in email security:

  • The email originates from a trusted domain

  • Authentication headers are valid

  • There is no malicious URL or executable content

  • The message relies purely on contextual manipulation

Because most controls focus on who sent the message, rather than what the message is trying to make the user do, these attacks frequently pass through automated defenses.

This is a textbook example of living-off-the-land abuse, where attackers weaponize standard platform features instead of exploiting software vulnerabilities.

Why This Matters

This technique erodes one of the strongest trust signals users rely on. A verified sender. When users see an email that is genuinely from Zoom, their suspicion drops. Attackers exploit this trust to push victims toward urgent, phone-based social engineering.

The attack also illustrates a broader trend. Modern phishing does not always require malware, fake domains, or technical exploitation. In many cases, legitimate systems are behaving exactly as designed, but are being misused in ways security controls were not built to detect.

DIAMATIX Perspective

From a defensive standpoint, this campaign reinforces a critical shift organizations must make. Email security can no longer rely solely on sender reputation and authentication checks.

Security teams should:

  • Treat verified SaaS emails as potential attack surfaces, not implicit trust anchors

  • Expand phishing detection to include content intent analysis, not just indicators of compromise

  • Train users to question urgency and cross-service inconsistencies (e.g. Zoom email referencing PayPal activity)

  • Review alert escalation playbooks for TOAD-style attacks that lack traditional technical indicators

As attackers increasingly exploit trusted platforms, detection must evolve from validating infrastructure to understanding attacker intent.

Contact DIAMATIX

Trusted · Innovative · Vigilant


Used Sources

  • Prophet Security. Technical analysis of Zoom-based TOAD phishing campaign

  • Zoom. Official authentication email behavior and account display name rendering

  • Industry research on TOAD (Telephone-Oriented Attack Delivery) techniques and living-off-the-land phishing

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.