logo

Advanced fake Zoom installer used for delivering malware · Blog · Sublime Security

ID: 28d65fd8-feae-5239-8b89-8f6fe7d442bd

STIX ID: report--28d65fd8-feae-5239-8b89-8f6fe7d442bd

Feed Name: Sublime Security Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-05-01

...
...

## Executive summary Sublime observed an active email campaign that impersonates Zoom meeting invites (likely AI-generated) and lures Windows users to an interactive JavaScript fake Zoom page; victims are coaxed to download a file named ZoomUpdateInstaller.msi which installs a maliciously-configured ScreenConnect remote access tool, granting attackers control of compromised systems. The report includes attack flow details, example JavaScript used to simulate attendees/voices, the malicious download URL structure, and detection signals used by Sublime's AI detection engine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.