Fake Zoom Update Scam Infects 1,437 Users, Deploys Surveillance Malware In Just 12 Days

A sophisticated phishing campaign has infected 1,437 Windows users in just 12 days by abusing trust in Zoom updates. Instead of deploying traditional malware, attackers abused a legitimate employee-monitoring product to spy on victims secretly.

Security researchers found the operation centered on a fake Zoom meeting page hosted. The website convincingly mimics a real Zoom waiting room. When a visitor lands on the page, it silently notifies attackers that someone has arrived.

A Fake Meeting That Feels Real

The scam begins when a user clicks what appears to be a Zoom invite link. The page loads a meeting interface showing three scripted participants “Matthew Karlsson,” “James Whitmore,” and “Sarah Chen.”

Each joins with a realistic Zoom chime, and looping background conversation audio plays. However, the interaction is staged.

The audio and participant sequence only begin after a real user clicks or types on the page. Automated security scanners that do not interact with the site may see nothing suspicious.

A permanent “Network Issue” warning appears over the video window. The lag and broken audio are intentional. The goal is psychological: frustrate the user into believing Zoom is malfunctioning.

Ten seconds later, a forced pop-up appears: “Update Available A new version is available for download.” A countdown runs from five to zero with no option to close it.

When the timer ends, a malicious file is automatically downloaded. At the same time, the page switches to a fake Microsoft Store screen showing “Zoom Workplace” installing.

While the victim watches the fake install animation, the real file quietly lands in the Downloads folder.

Legitimate Software, Criminal Intent

A fake Zoom website (Source: malwarebytes)
A fake Zoom website (Source: malwarebytes)

The downloaded file is a Windows MSI installer named:

IndicatorValue
SHA-256 Hash644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa
Domainuswebzoomus[.]com
MSI Filenamezoom_agent_x64_s-i(__941afee582cc71135202939296679e229dd7cced)(1).msi
Teramind ID941afee582cc71135202939296679e229dd7cced
Install PathC:\ProgramData{4CEC2908-5CE4-48F0-A717-8FC833D8017A}
Service Nametsvchst
C2 Serverrt.teramind.co

Analysis revealed the installer contains a modified version of Teramind, a legitimate workforce monitoring solution.

Businesses use Teramind to log keystrokes, capture screenshots, monitor websites, record clipboard activity, and track file access on company-owned devices.

In this campaign, criminals preconfigured the installer to connect to an attacker-controlled Teramind server. Hidden configuration fields such as “Agent version 26.3.3403” and “Server IP or host name” confirm it was prepared for remote surveillance.

The installer uses Teramind’s legitimate “stealth mode,” designed for enterprise deployments. In this case, it installs silently under C:\ProgramData{GUID}, often disguising its main process as dwm.exe. It may also create a service such as tsvchst to maintain persistence.

Notably, the software includes logic to detect sandbox or debugging environments, helping it evade security researchers. Once installation completes, temporary files are deleted, leaving minimal traces.

There is no custom malware code to flag. The files are part of a real commercial product. Traditional antivirus tools may not detect it because the software itself is legitimate only its deployment is malicious.

What To Do

Malwarebytes said, if you downloaded the file:

  • Do not open it.
  • If executed, treat the system as compromised.
  • Check C:\ProgramData for suspicious GUID folders.
  • Run sc query tsvchst in Command Prompt (admin).
  • Change passwords from a clean device.
  • Contact IT immediately if this occurred on a work computer.

This campaign highlights a growing trend: attackers increasingly weaponize legitimate enterprise tools. A quick habit typing zoom.us directly instead of clicking unknown links can prevent becoming the next victim.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories