Fake Zoom meeting “update” silently installs rogue version of monitoring tool abused by cybercriminals to spy on victims
ID: 14c258c6-48ea-5bcb-a737-862ba79df97c
STIX ID: report--14c258c6-48ea-5bcb-a737-862ba79df97c
Feed Name: Malwarebytes Blog
A malicious campaign hosts a convincing fake Zoom waiting-room page that, after minimal user interaction, forces an automatic download of a Windows MSI which silently installs a preconfigured, stealth-mode Teramind monitoring agent tied to an attacker-controlled instance. The installer uses social engineering (fake Microsoft Store UI) to conceal activity, includes sandbox/analysis detection, removes staging artifacts after installation, and results in persistent, consent-free surveillance (stalkerware-like behavior). The report provides a SHA-256 hash, the Teramind instance ID, detection/remediation steps (check ProgramData and service tsvchst, change passwords, contact IT), and recommendations to open Zoom only from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
