Hidden Hackers in Your Zoom Call? New Cyberattack Disguises Malware as Virtual Meetings

Listen to this Post

Featured Image

Covert Cyber Threat Discovered at Black Hat 2025

A startling discovery made at Black Hat USA 2025 has sent shockwaves through the cybersecurity world. Security experts have uncovered a novel and highly stealthy attack technique that leverages web conferencing platforms — tools we all rely on daily — to launch hidden command and control (C2) operations. By blending in with the digital noise of normal business meetings, attackers can now slip under the radar of traditional security systems with chilling precision.

The breakthrough was presented by Adam Crosser, a Staff Security Engineer at Praetorian, who demonstrated how hackers can transform seemingly harmless video calls into backdoors for serious cyber intrusions. Using real-time communication protocols and an open-source tool called TURNt, the technique mimics enterprise collaboration traffic so effectively that even trained security systems may struggle to tell the difference.

This new approach doesn’t just increase bandwidth and stealth — it allows real-time attacks, proxy tunneling, hidden virtual network computing (VNC) sessions, and deeper pivoting inside corporate networks. It raises serious alarms for businesses across all industries, especially as remote work remains dominant. The threat is not theoretical — it’s real, operational, and already in testing by red team operators.

Real Meetings, Fake Traffic: The New Cybercrime Cloak

Exploiting the Familiar to Create the Undetectable

At the core of this technique is TURNt, a tool that routes covert traffic through media servers used by mainstream conferencing platforms. These servers are trusted, widely whitelisted, and often bypass traditional inspection because enterprises need them for reliable video calls. But therein lies the danger.

TURNt hijacks these trusted relays to camouflage malicious traffic under the guise of normal conference behavior. When organizations exempt conferencing providers from TLS (Transport Layer Security) inspection — as many do for performance reasons — attackers gain a blind spot to move freely and quietly.

This

Security Tools Struggle to Keep Up

The method exposes a significant flaw in current enterprise security strategies: heavy reliance on whitelisted traffic and legacy network monitoring tools. Since malicious activity hides inside “legitimate” conferencing data, many tools won’t flag it, and alerts may never trigger.

As more companies push toward hybrid or remote work environments, video conferencing tools become an Achilles’ heel. Organizations need to rethink how they treat conferencing traffic. Simply trusting provider IPs and skipping inspection can no longer be considered a safe practice.

Defensive strategies must now include behavioral detection, pattern analysis, and anomaly monitoring within encrypted conferencing streams. Crosser’s presentation urged enterprises to revise their security policies, build custom alerting rules, and invest in visibility at the media transport layer.

What Undercode Say:

TURNt and the Death of Trust-Based Whitelisting

The release of TURNt represents a paradigm shift in how attackers approach network infiltration. Historically, C2 communication depended on methods that were either too noisy or too slow to be practical for extended engagements. But with TURNt, cybercriminals have solved the bandwidth and detection problem by piggybacking on video conferencing — something that’s both high-bandwidth and heavily trusted.

This attack vector thrives on a core weakness in enterprise environments: blind trust. Companies routinely whitelist conferencing services to avoid latency issues and reduce false positives. However, this trusted infrastructure is now being hijacked to serve malicious purposes, undermining one of the foundational assumptions in network security design.

The brilliance of this method lies in its subtlety. While traditional covert channels are detectable with pattern analysis, TURNt sessions look exactly like what they claim to be — legitimate meetings. Packet signatures, bandwidth usage, and source IPs all match expected behavior, making detection incredibly difficult without deep inspection and cross-context monitoring.

Even more concerning is how the dual-channel structure mimics typical usage patterns. A long-lasting low-noise connection that suddenly spikes for a two-hour “meeting” fits right into enterprise norms. It’s a Trojan horse designed not to break the walls, but to walk through the front door unnoticed.

Enterprise Defenders Face an Uphill Battle

Current intrusion detection systems are ill-equipped to spot this threat. Few businesses have tools that can inspect TURN traffic in real time, let alone distinguish between legitimate screen sharing and covert lateral movement across the network. Even more alarming is the potential for persistent access: TURNt can maintain communication even during downtime, allowing attackers to come and go at will.

Defensive measures will need to evolve rapidly. Behavior-based detection and contextual traffic analysis will become non-negotiable. This includes flagging sessions with unusual internal behaviors, such as repeated access to sensitive internal systems during “calls,” or extended bandwidth use from unlikely user accounts.

Security teams should also consider deploying deception technologies or honeypots within conferencing environments to identify misuse. Incorporating AI-driven anomaly detection can help distinguish a real video call from a fake one, even when packet behavior looks normal.

In addition, organizations must educate their security staff about the risks of blindly trusting conferencing IP ranges. IT teams should implement stricter logging, apply TLS inspection where feasible, and establish baseline patterns for conference-related network activity. Anything outside the norm must be investigated.

Collaboration Platforms Become the New Battleground

As remote work continues to define the modern workplace, collaboration tools have become the central nervous system of business operations — and attackers know it. This shift has made these platforms prime real estate for cyber exploitation. TURNt and techniques like it are only the beginning.

Expect more sophisticated adaptations in the future, where machine learning and behavioral mimicry will allow attackers to simulate entire meeting environments. As platforms evolve, so too will the tactics. What looks like a sales meeting today might be a malware drop session tomorrow.

Enterprises must stop thinking of collaboration tools as utility software and start treating them like core security assets. Protecting them is no longer optional — it’s essential to organizational survival in a post-TURNt world.

🔍 Fact Checker Results:

✅ TURNt is an open-source tool publicly demonstrated at Black Hat USA 2025
✅ The method exploits whitelisted media servers from conferencing providers
❌ Most traditional network tools can detect this — False, they often fail due to traffic mimicking

📊 Prediction:

Expect a surge in TURNt-style attacks over the next 12–18 months 🚨
Cybercriminals will increasingly exploit video conferencing as a safe haven for C2 communication 📡
Security vendors will rush to develop inspection tools tailored to media protocols like STUN/TURN/ICE 🧠

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon