216.73.217.22

Be Careful With Fake Zoom Client Downloads

· Published 05/06/2025 15:35 · Modified 05/06/2025 17:16

Export JSON

Essential information

Published
05/06/2025 15:35
Modified
05/06/2025 17:16
Tags
2025-06-05 downloader fake update phishing remote access tool screenconnect zoom
Related entities
2 observables, 6 techniques (mitre), 1 malware

Description

A deceptive email containing a fake meeting invitation has been identified. Clicking the 'join' button leads to a website prompting users to install a purported client update. The downloaded executable, 'Session.ClientSetup.exe', is actually malware that installs an MSI package. This package deploys , a , allowing attackers to gain unauthorized access to the victim's computer. The malware establishes persistence by installing itself as a service and connects to a command and control server at tqtw21aa.anondns.net on port 8041. Users are advised to exercise caution when receiving unexpected invitations or update prompts.

External references