Phishing Pages for Zoom and Google Meet Install Monitoring Tool
ID: 01e15806-35c9-5550-ab84-fa435483e2c7
STIX ID: report--01e15806-35c9-5550-ab84-fa435483e2c7
Feed Name: HackRead
Researchers documented a phishing campaign that uses convincingly faked Zoom and Google Meet waiting rooms (including audio cues and a simulated ‘network issue’) to coerce visitors into downloading an installer that deploys a stealth-configured Teramind monitoring agent. The operation leverages fake update prompts and Microsoft Store-like screens to mask the payload delivery; the deployed software can log keystrokes, capture screenshots, harvest browsing and clipboard data, and connect to attacker infrastructure for remote monitoring. The campaign reuses installers across domains and highlights how legitimate enterprise monitoring tools can be abused, with recommended mitigations including verifying meeting links and obtaining applications/updates only from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
