Zoom and Teams Apps Targeted By Signed Malware Carrying RMM Backdoors

In February 2026, Microsoft Defender Experts identified multiple phishing campaigns targeting workplace applications such as Zoom and Teams.

These campaigns were attributed to an unknown threat actor using advanced social engineering techniques to deliver malicious executables disguised as legitimate software.

The emails included PDFs and links that appeared harmless but were actually designed to trick users into downloading malicious programs.

The threat actor used phishing emails with PDF attachments or links, often impersonating meeting invitations, invoices, or other organizational communications.

Once clicked, these links prompted users to download executable files that appeared to be legitimate software, such as msteams.exe, trustconnectagent.exe, adobereader.exe, zoomworkspace.clientsetup.exe, and invite.exe.

What made this campaign particularly dangerous was the use of a trusted Extended Validation (EV) certificate issued to TrustConnect Software PTY LTD.

This allowed the malicious files to be digitally signed, giving them a false sense of legitimacy and making them harder to detect.

After execution, these applications deployed Remote Monitoring and Management (RMM) tools, such as ScreenConnect, Tactical RMM, and MeshAgent, enabling the attackers to maintain persistent access and move laterally across the compromised environment.

Signed Malware Targets Zoom Teams (Source: microsoft)
Signed Malware Targets Zoom Teams (Source: microsoft)

In one of the observed campaigns, the attackers distributed PDF attachments that, when opened, displayed a blurred image meant to mimic a restricted document.

The PDF contained a red button labeled “Open in Adobe” that redirected users to a fake Adobe download page. The page then tricked users into downloading a malicious file masquerading as Adobe Acrobat Reader, which was in fact an RMM tool signed by TrustConnect Software PTY LTD.

Campaign Delivering Meeting Invitations

Another variation of the phishing campaign targeted users with emails that appeared to be legitimate Teams or Zoom meeting invitations.

Email containing PDF attachment (Source: microsoft)
Email containing PDF attachment (Source: microsoft)

These emails often included lures such as project bids or financial updates. Users were prompted to click on links that led to fake update prompts for Microsoft Teams, Zoom, or Google Meet.

When the victim followed these prompts, the download turned out to be an RMM tool. Again, the software was digitally signed with the same TrustConnect certificate, reinforcing the attack’s credibility.

Content inside the counterfeit PDF attachment (Source: microsoft)
Content inside the counterfeit PDF attachment (Source: microsoft)

Once the fake Teams or Zoom application was installed, it created a copy of itself in the C:\Program Files directory, disguising itself as a legitimate system-installed application.

Mitigation and Protection Guidance

To mitigate the impact of these types of attacks, Microsoft recommends several steps organizations should consider using Windows Defender Application Control or AppLocker to block unapproved IT management tools, including unauthorized RMM software.

It is also advised to implement multifactor authentication (MFA) for approved RMM systems.

Furthermore, security teams should regularly audit their environment for unauthorized RMM installations and use cloud-delivered protection to block new and evolving threats.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories