Tag: Ghost Calls

New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations
News

New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations

The 'Ghost Calls' post-exploitation command-and-control (C2) evasion technique exploits TURN servers, which are utilized by conferencing applications like as Zoom and Microsoft Teams, to tunnel traffic over reliable infrastructure. Ghost Calls circumvents the majority of current protections and anti-abuse mechanisms without the use of an attack by using WebRTC, genuine credentials, and proprietary tooling. Adam Crosser, a security researcher at Praetorian, demonstrated this novel strategy at BlackHat USA, emphasizing that Red Teams can employ it for penetration emulation exercises. According to the presentation's briefing, we make use of web conferencing protocols, which are built for low-latency, real-time communication and run on globally dispersed media servers that act as org...