logo

Fake Zoom and Google Meet Phishing Campaigns Deploy Teramind Surveillance Software

ID: 0ffa13d2-6209-538b-a451-76dfb29c620e

STIX ID: report--0ffa13d2-6209-538b-a451-76dfb29c620e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

Threat actors are running phishing lures impersonating Zoom and Google Meet to silently install an unmodified Teramind MSI in “Hidden Agent” mode on Windows hosts; the installer extracts an instance ID from the filename, checks connectivity to a hardcoded C2 (rt.teramind.co), and only proceeds if reachable. The deployed implant hides UI, exposes SOCKS5 proxy support, installs resilient LocalSystem services (tsvchst/pmon), loads kernel drivers (tm_filter.sys, tmfsdrv2.sys), and includes IOCs (file hashes, domains, service names and a ProgramData GUID) along with recommended mitigations and removal steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.