跳到正文
北京时间
原文
PromptArmor:Threat Intelligence·· 2026-08-10精选AI 评分72

PromptArmor 披露攻击者可接管 ZoomMate 窃取 Zoom 及关联服务数据

Attacker Takes Over Zoom AI

AI 导读

PromptArmor 披露针对 Zoom AI 智能体 ZoomMate 的攻击链:恶意 Skill 或间接提示词注入可让智能体连到攻击者服务器并执行命令,窃取会议记录、消息及连接器数据。攻击在用户点击 stop 或关闭 Zoom 后仍持续运行,且最终聊天输出看起来完全正常。作者称 ZoomMate 的联网环境属预期功能,无特定漏洞可披露,发文旨在提醒用户无严格网络沙箱的智能体风险。

推荐理由

原文由安全团队披露完整攻击链,说明恶意 Skill 或提示词注入可在用户无感知下持续窃取 Zoom 及关联服务数据。

正文
Attacker takes over the victim’s Zoom AI, exfiltrating data from across Zoom and connected services
Attacker takes over the victim’s Zoom AI, exfiltrating data from across Zoom and connected services

Context

Zoom’s flagship AI feature is ZoomMate, an agentic chatbot that operates on data from across a user’s Zoom account and any connected services (e.g., OneDrive, Google, connectors, etc). The agent appears to have been given an environment with unrestricted HTTPS network access, with no user or admin-level configuration to lock it down.

In this article, we explore how a malicious Skill (or a prompt injection) can manipulate Zoom’s agent into connecting to an attacker’s server, allowing the attacker to issue their own commands and exfiltrate data from the victim’s tenant.

Further compounding this risk, the attacker’s connection can remain active even if the user clicks ‘stop’ on the agent and closes Zoom. Additionally, the final chat output to the user appears completely normal.

ZoomMate’s widely capable environment with internet access appears to be an intended functionality. There does not appear to be any specific vulnerability or programmatic component that is not working as intended to be disclosed to Zoom. We are publishing this article to inform users who may not be aware of the risk they are accepting by utilizing an agentic chatbot without strict network sandboxing.

The Attack Chain

  1. The victim asks for a report on their meetings for the week

    Victim asks ZoomMate to create a weekly meeting report
    Victim asks ZoomMate to create a weekly meeting report
  2. The victim is using a Skill they have uploaded to Zoom

    Note: The attack in this article can also be conducted without a Skill, via indirect prompt injection (e.g., a hidden instruction Zoom ingests, such as an email).

    Skills are typically distributed through online marketplaces and can be shared between users within Zoom; prior research shows that attackers are uploading malicious Skills to these online registries.

    The uploaded weekly-meeting-report Skill listed among installed Zoom Skills
    The uploaded weekly-meeting-report Skill listed among installed Zoom Skills

    Note: Zoom does offer users a warning when uploading a Skill, but we do not believe it adequately informs them of the risks. The warning: “This skill is not from Zoom's official catalog and hasn't been verified by Zoom. Make sure you trust this skill's creator before installing.”

  3. Zoom AI runs code from the malicious Skill

    Even if the user clicks the ‘stop’ button or closes Zoom, the attack does not stop because it continues to run in the agent’s environment on Zoom’s servers.

    The code in the malicious Skill makes network requests (HTTPS) to an attacker’s server every few seconds, asking the server for commands to run. When the attacker sends a command, the script executes it in Zoom’s environment and sends the results back to the attacker’s server.

    ZoomMate executing the malicious script from the Skill
    ZoomMate executing the malicious script from the Skill
  4. The attacker sends commands to exfiltrate meeting transcripts, messages, data from connectors, and more

    Attacker runs commands to exfiltrate data from across Zoom and connected apps
    Attacker runs commands to exfiltrate data from across Zoom and connected apps

    Note: The attacker can target data from across Zoom that ZoomMate has access to, including connected data sources. It has not been confirmed whether the attacker can exploit Zoom’s browser integration to exfiltrate data from other websites.

  5. A normal-looking report is delivered to the user, and the attacker stays connected

    Report output and chat look normal while the attacker can keep running commands even after ZoomMate stops
    Report output and chat look normal while the attacker can keep running commands even after ZoomMate stops

来源:PromptArmor:Threat Intelligence · promptarmor.com