Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)

PremiumReviewedSigma · Low · v1
Category
proxy
Author
HuntRule
Published
2026-09-07
Updated
2026-09-07

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects traffic to the local ZoomOpener helper webserver launch endpoint on loopback port 19421. This maps to the Zoom drive-by RCE chain where a webpage sends a crafted launch request to the hidden local server. An attacker leverages this to trigger silent installation and code execution on the victim host.

Related detections6 linkedT1189 — drag to rearrange
Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)
Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
Suspicious Child Processes Spawned by Browsers on macOS
Webserver GET requests containing XSS-related payload strings
Proxy Web Requests for Flash Player Installer from Unofficial Locations
Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
Pivot detection · T1189 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.