Phishing Campaigns Target Users with Fake Meeting Invites and Update Alerts via Zoom, Teams, and Google Meet
ID: 322dc539-7c75-543b-9ce5-2ccd2b864165
STIX ID: report--322dc539-7c75-543b-9ce5-2ccd2b864165
Feed Name: GBHackers
Ongoing phishing campaigns impersonate Zoom/Teams/Google Meet invites and prompt victims to install a fake “critical update” that installs legitimately signed RMM software (e.g., Datto RMM, LogMeIn, ScreenConnect), enabling attackers persistent remote access for data theft, lateral movement, and possible ransomware deployment; attackers use typo‑squatted domains and convincing fake meeting/login pages, and Netskope Threat Labs recommends monitoring RMM usage, restricting admin privileges, and ensuring updates come only from vendor domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
