Phishing Attacks Leverage Zoom, Teams, Google Meet Invites

A surge in phishing campaigns that hijack the trust users place in video conferencing tools like Zoom, Microsoft Teams, and Google Meet. Attackers send fake meeting invites to corporate employees, urging them to join urgent calls.

Once victims click, they land on convincing fake pages that mimic the real apps. These pages show participant lists with names “joining” in real time, building a sense of authenticity and pressure not to miss out.

The trap springs when users try to enter the call. A pop-up warns that an app version is outdated or incompatible. To join, victims must download and run a “mandatory software update.”

This leads to typo-squatted domains like zoom-meet.us, where the payload awaits. Disguised as an innocent fix, the file prompts users to ignore security warnings, exploiting the rush of business schedules.

The Hook: Fake Updates Hide Dangerous Tools

Attackers craft pixel-perfect phishing sites that mirror official Zoom, Teams, and Google Meet interfaces. Victims see familiar layouts, complete with dynamic elements like adding participants to heighten urgency.

Phishing Exploits Zoom Teams Meet (Source: netskope)
Phishing Exploits Zoom Teams Meet (Source: netskope)

The phishing page then blocks access, claiming a software glitch. It offers step-by-step instructions to “update” the app, such as downloading from a bogus link.

The downloaded file is not a harmless patch. It’s a digitally signed executable or MSI installer, renamed to blend in like GoogleMeet.exe or ZoomWorkspaceinstallersetup.msi.

Netskope researchers identified three main remote monitoring and management (RMM) tools as payloads: Datto RMM, LogMeIn Unattended, and ScreenConnect. These legitimate enterprise tools come with valid digital signatures from trusted authorities.

Phishing Exploits Zoom Teams Meet (Source: netskope)
Phishing Exploits Zoom Teams Meet (Source: netskope)

In corporate settings, they often pass through antivirus filters and even endpoint detection because IT teams pre-approve them for remote support.

Once installed, the RMM agent grants attackers full administrative remote access. They can view screens, transfer files, run shells, and share control all without custom malware that might trigger alerts.

This foothold lets threat actors steal data quietly, scout networks for high-value targets, or deploy ransomware across endpoints. The high-trust nature of video calls makes this vector deadly, as users bypass defenses to avoid “missing” a meeting.

Netskope Threat Labs tracked these campaigns exploiting the post-pandemic reliance on virtual meetings. Phishing emails mimic internal invites, often spoofing executive names.

The fake sites urge quick action, with timers or participant counts to create FOMO. Some even simulate audio cues or chat messages. Redirects to malicious domains occur seamlessly, evading email filters tuned to detect obvious spam.

Defend Against RMM Phishing in Video Invites

Organizations face rising risks from attacks that blend social engineering with legitimate tech. Security teams should train users to verify invites via direct app links or contacts, never external downloads.

Enable multi-factor authentication on email and enforce strict app allowlisting. Tools like Netskope’s cloud access security brokers can inspect traffic to phishing domains and block RMM payloads.

Phishing Exploits Zoom Teams Meet (Source: netskope)
Phishing Exploits Zoom Teams Meet (Source: netskope)

Endpoint protection must evolve beyond signatures. Behavioral analysis detects anomalous RMM use, like unexpected admin access from unknown IPs.

Monitor for unusual outbound connections to RMM servers. Patch management is key keep video apps updated to reduce “incompatibility” pretexts.

Indicator TypeDetailsSource
Domainszoom-meet.us, teams-update.net (examples from campaigns)Netskope Threat Labs
FilenamesGoogleMeeet.exe, ZoomWorkspaceinstallersetup.msiNetskope Analysis
RMM ToolsDatto RMM, LogMeIn Unattended, ScreenConnectObserved Payloads

These indicators help threat hunters spot infections early. Regular simulations of phishing scenarios build user resilience.

This campaign shows how attackers weaponize daily tools against rushed workers. By posing as updates for trusted apps, they secure persistent access via signed RMM agents.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories