logo

Fake Zoom, Teams Meeting Invites Use Compromised Certificates to Drop Malware

ID: 1826b629-1d48-529e-a7e3-411684a882be

STIX ID: report--1826b629-1d48-529e-a7e3-411684a882be

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Microsoft researchers reported a phishing campaign that leverages stolen Extended Validation code‑signing certificates to make malicious fake-updater binaries appear trusted; these binaries delivered RMM backdoors (ScreenConnect, MeshAgent) via meeting-invite lures and fake download pages, enabling persistent privileged access and enabling credential theft or ransomware — defenders should distrust email update prompts, verify distribution channels, and evaluate signatures alongside runtime behavior and reputational telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.