216.73.217.22

Fake Zoom meeting 'update' silently installs unauthorized version of monitoring tool abused by cybercriminals to spy on victims

· Published 01/03/2026 05:26 · Modified 02/03/2026 11:42

Export JSON

Essential information

Published
01/03/2026 05:26
Modified
02/03/2026 11:42
Tags
2026-03-01 fake update social engineering stealth installation teramind abuse valleyrat workforce monitoring zoom impersonation
Related entities
2 observables, 8 techniques (mitre), 1 malware, 1 others

Description

A sophisticated scam campaign is targeting users with a fake Zoom meeting website that automatically downloads and installs an unauthorized version of Teramind, a legitimate solution. The attackers create a convincing imitation of a Zoom video call, complete with fake participants and audio, to lure victims. After a short delay, an 'Update Available' prompt appears, leading to the silent installation of the monitoring software. The altered Teramind installer is configured to run stealthily and avoid detection by security tools. This campaign is particularly dangerous as it misuses legitimate commercial software, making it difficult for traditional antivirus tools to detect. The attackers gain full surveillance capabilities over the victim's device, including keylogging, screen capture, and file monitoring.

External references