Zoom Update Scam Infects 1,437 Users in 12 Days to Deploy Surveillance Tools
ID: c48f72bc-f183-5e44-bf78-d92fc020be69
STIX ID: report--c48f72bc-f183-5e44-bf78-d92fc020be69
Feed Name: GBHackers
A scam web page mimicking Zoom (uswebzoomus.com) tricks users into downloading a malicious MSI named like a Zoom agent which installs a preconfigured Teramind monitoring agent as a stealth background service (dwm.exe) under C:\ProgramData\{GUID}. The agent captures keystrokes, screenshots, application usage and clipboard data, evades analysis and many AV products by using legitimate Teramind binaries, and was observed infecting 1,437 Windows users over 12 days; IOCs include a SHA-256 hash, the domain, and a Teramind instance ID.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
