Zoom Update Scam Infected 1,437 Users to Deploy Surveillance Tools in 12 Days
ID: 4071833c-ca93-542c-8f74-3ddc4ffe0c1f
STIX ID: report--4071833c-ca93-542c-8f74-3ddc4ffe0c1f
Feed Name: cybersecurityNews.com
A fake Zoom waiting-room website (uswebzoomus.com) delivered a repackaged Teramind monitoring agent (SHA-256: `644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa`) that silently installed as `dwm.exe` under C:\\ProgramData\\{4CEC2908-5CE4-48F0-A717-8FC833D8017A} and persisted via a `tsvchst` service; the agent logs keystrokes, screenshots, clipboard contents and exfiltrates data, evading detection by using stealth build paths and debug-environment checks. Security teams are advised to block the domain and hash, search for the indicated install path and service, treat affected hosts as compromised, and reset credentials from a clean device.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
