Ghost Calls: Abusing Web Conferencing for Covert Command & Control (Part 2 of 2)
In part one, we discussed the architecture of web conferencing applications, with a specific focus on Zoom’s architecture to support web conferencing at a massive global scale. Part two will discuss the approach we developed to support tunneling traffic through Zoom and Microsoft Teams using the TURN protocol. Let’s start with a quick recap of […]
Ghost Calls: Abusing Web Conferencing for Covert Command & Control (Part 1 of 2)
Web conferencing covert C2 turns the most trusted traffic on an enterprise network, the daily Zoom and Teams calls defenders are told to exempt from inspection, into an interactive command-and-control channel. In the middle of a particularly tight red team engagement, we hit a familiar wall. Our long-term implant was rock solid: quiet, persistent, and […]