Threat group linked to Sandworm discovered weaponizing Zoom's annotation tool in targeted attacks using fake job offers.
A Russian-linked hacking group has been caught using a surprisingly simple method to break into computers during video conferences. The attackers send fake job interview invitations to targets, asking them to join Zoom calls. Once the meeting starts, they exploit a hidden weakness in Zoom's annotation feature—the tool that lets people draw and write on shared screens during presentations. Through this flaw, hackers can slip malicious code onto victims' computers without requiring any action from the people in the call.
The attack works in both directions. If you're presenting and sharing your screen, the hackers watching could take control of your computer. If you're just watching someone else present, the attackers could seize your machine instead. Think of it like someone being able to reach through your computer monitor and take control of your keyboard and mouse without you knowing it happened.
The group responsible is called UAC-0145, and security researchers believe they have connections to Sandworm, a notorious state-sponsored hacking operation. Their strategy here shows a shift toward social engineering—using psychological tricks like fake job offers to get people to lower their guard. Rather than simply hacking their way in, they're inviting victims to open the door themselves.
This discovery reveals a significant gap in how video conference tools handle security. The annotation feature was likely designed to make meetings more interactive and collaborative, but the programmers who built it didn't anticipate someone weaponizing it for remote takeovers. It's similar to discovering that the window locks on a building aren't actually connected to anything—they look secure, but they don't actually work.
The incident shows that even well-established platforms used by millions of people can harbor serious vulnerabilities. Zoom has become essential infrastructure for remote work, education, and business. When flaws like this exist, they potentially affect countless organizations and individuals who depend on these services daily.
If your company uses Zoom for meetings, this matters directly to you. Your personal files, passwords, emails, and sensitive work documents could be compromised. The attackers could install spyware that watches everything you do on your computer for weeks or months without your knowledge.
Immediate steps: Update Zoom to the latest version immediately. Zoom released a patch to fix this vulnerability, so this protection is available right now.
For job hunters: Be cautious about interview requests from unknown companies. Verify that job postings are legitimate before joining video calls. Check the company's official website and call their main phone number to confirm.
For your organization: Alert your IT department about this threat. They may want to implement additional protections or update their security policies around video conferencing.
General practice: Never assume a video call is completely safe just because it's from a recognized platform. Treat it like you'd treat any online interaction—stay skeptical of unexpected requests.
Staying informed and updating your software promptly remains your strongest defense against evolving cyber threats like this one.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →