logo

Phishing Pages for Zoom and Google Meet Install Monitoring Tool

ID: 01e15806-35c9-5550-ab84-fa435483e2c7

STIX ID: report--01e15806-35c9-5550-ab84-fa435483e2c7

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Waqas

...
...

Researchers documented a phishing campaign that uses convincingly faked Zoom and Google Meet waiting rooms (including audio cues and a simulated ‘network issue’) to coerce visitors into downloading an installer that deploys a stealth-configured Teramind monitoring agent. The operation leverages fake update prompts and Microsoft Store-like screens to mask the payload delivery; the deployed software can log keystrokes, capture screenshots, harvest browsing and clipboard data, and connect to attacker infrastructure for remote monitoring. The campaign reuses installers across domains and highlights how legitimate enterprise monitoring tools can be abused, with recommended mitigations including verifying meeting links and obtaining applications/updates only from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.