Fake Zoom and Google Meet Phishing Campaigns Deploy Teramind Surveillance Software
ID: 0ffa13d2-6209-538b-a451-76dfb29c620e
STIX ID: report--0ffa13d2-6209-538b-a451-76dfb29c620e
Feed Name: GBHackers
Threat actors are running phishing lures impersonating Zoom and Google Meet to silently install an unmodified Teramind MSI in “Hidden Agent” mode on Windows hosts; the installer extracts an instance ID from the filename, checks connectivity to a hardcoded C2 (rt.teramind.co), and only proceeds if reachable. The deployed implant hides UI, exposes SOCKS5 proxy support, installs resilient LocalSystem services (tsvchst/pmon), loads kernel drivers (tm_filter.sys, tmfsdrv2.sys), and includes IOCs (file hashes, domains, service names and a ProgramData GUID) along with recommended mitigations and removal steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
