logo

Fake Zoom meeting “update” silently installs rogue version of monitoring tool abused by cybercriminals to spy on victims

ID: 14c258c6-48ea-5bcb-a737-862ba79df97c

STIX ID: report--14c258c6-48ea-5bcb-a737-862ba79df97c

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-02-24

Date Updated: 2026-04-28

...
...

A malicious campaign hosts a convincing fake Zoom waiting-room page that, after minimal user interaction, forces an automatic download of a Windows MSI which silently installs a preconfigured, stealth-mode Teramind monitoring agent tied to an attacker-controlled instance. The installer uses social engineering (fake Microsoft Store UI) to conceal activity, includes sandbox/analysis detection, removes staging artifacts after installation, and results in persistent, consent-free surveillance (stalkerware-like behavior). The report provides a SHA-256 hash, the Teramind instance ID, detection/remediation steps (check ProgramData and service tsvchst, change passwords, contact IT), and recommendations to open Zoom only from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.