Fake Zoom, Teams Meeting Invites Use Compromised Certificates to Drop Malware
ID: 1826b629-1d48-529e-a7e3-411684a882be
STIX ID: report--1826b629-1d48-529e-a7e3-411684a882be
Feed Name: HackRead
**Executive summary:** Microsoft researchers reported a phishing campaign that leverages stolen Extended Validation code‑signing certificates to make malicious fake-updater binaries appear trusted; these binaries delivered RMM backdoors (ScreenConnect, MeshAgent) via meeting-invite lures and fake download pages, enabling persistent privileged access and enabling credential theft or ransomware — defenders should distrust email update prompts, verify distribution channels, and evaluate signatures alongside runtime behavior and reputational telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
