Press play to start listening
Cybersecurity researchers at Cofense have identified a phishing campaign targeting universities, particularly those affiliated with healthcare organizations. The research reveals that threat actors are sending emails that falsely allege sexual misconduct violations to trick recipients into installing an abused version of the legitimate Zoho Assist remote access tool, which Cofense refers to as Zoho RAT.
How the Attack Works
The malicious emails spoof university letterheads and email domains while copying the signature blocks of university leaders. In documented attempts, attackers impersonated the president or dean of institutions including:
- Notre Dame
- The University of Virginia,
- The Medical College of Wisconsin.
Cofense found that the emails largely followed the same template, with the university leader’s name and signature details changed between campaigns.
“Although the current iteration of this campaign appears to use a simple generative program, it is already enough to bypass current Integrated Cloud Email Security (ICES) controls,” Cofense researchers noted in the blog post shared with Hackread.com.
The emails claim that a Title IX or sexual misconduct issue involving a student or staff member needs attention. The emails do not contain a malicious attachment. A link first takes the recipient to a Google Drive file containing another link that downloads the abused Zoho RAT instance.
The phishing email tells the recipient to download and install Zoho Assist and even provides installation instructions. It refers to the installer as AZ_Access_My_Department.
Cofense said the Google Drive link can help the emails get past some security checks before the recipient reaches the Zoho RAT download. Researchers also found the RAT installer hosted on abused cloud services and threat actor-controlled domains, with the actor-controlled domains typically registered less than a month earlier.
Abuse of Zoho RAT Assist
Zoho RAT is a legitimate remote access program, but Cofense describes the abused instance as a Zoho RAT. Once installed, it can allow attackers to view and control the screen, transfer files, and deliver additional files, including ransomware.
However, its use in attacks is not limited to this campaign. In June 2026, Microsoft reported an intrusion in which an attacker used Zoho Assist along with other legitimate remote-access tools during the attack.
Healthcare-Linked Universities Targeted
More than 80% of the targets identified by Cofense were healthcare-related universities, including medical colleges and teaching hospitals. Healthcare and Public Health is one of the 16 critical infrastructure sectors in the US.
CISA says disruption to critical infrastructure can have a debilitating effect on national security, economic security, public health, or safety.
In this campaign, the attackers are using phishing emails to convince recipients to install legitimate remote-access software for malicious purposes. Cofense recommends checking unusual software installation requests through another channel and monitoring systems for signs of compromise.
(Image by JetalProduções from Pixabay)
