logo

Phishing Campaigns Target Users with Fake Meeting Invites and Update Alerts via Zoom, Teams, and Google Meet

ID: 322dc539-7c75-543b-9ce5-2ccd2b864165

STIX ID: report--322dc539-7c75-543b-9ce5-2ccd2b864165

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Ongoing phishing campaigns impersonate Zoom/Teams/Google Meet invites and prompt victims to install a fake “critical update” that installs legitimately signed RMM software (e.g., Datto RMM, LogMeIn, ScreenConnect), enabling attackers persistent remote access for data theft, lateral movement, and possible ransomware deployment; attackers use typo‑squatted domains and convincing fake meeting/login pages, and Netskope Threat Labs recommends monitoring RMM usage, restricting admin privileges, and ensuring updates come only from vendor domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.