Phishing Campaigns Target Users with Fake Meeting Invites and Update Alerts via Zoom, Teams, and Google Meet
An increasing number of phishing campaigns are utilizing fake meeting invitations from widely-used video conferencing platforms such as Zoom, Microsoft Teams, and Google Meet. These attacks employ social engineering tactics to deceive corporate users…
An increasing number of phishing campaigns are utilizing fake meeting invitations from widely-used video conferencing platforms such as Zoom, Microsoft Teams, and Google Meet. These attacks employ social engineering tactics to deceive corporate users into downloading malicious "software updates." These updates are actually digitally signed remote monitoring and management (RMM) tools, granting attackers full remote access to victims' systems.
The phishing operations exploit trusted collaboration platforms, which are essential in hybrid and remote work environments. Attackers impersonate corporate communication channels by sending convincing email invitations that mimic legitimate meeting notifications. Users are prompted to join a meeting or verify an invite through deceptive links hosted on typo-squatted domains like zoom-meet.us or teams-updates.net, closely resembling legitimate corporate services.
Upon clicking the fake link, victims are redirected to a phishing page that closely resembles the authentic login or meeting screen of platforms like Google Meet, Microsoft Teams, or Zoom. These pages often display lists of participants who have "joined" the call to increase credibility.
To further reinforce legitimacy, these pages may display simulated participant lists and active meeting interfaces, creating a sense of urgency to "join immediately." Netskope researchers observed that these interactive decoys encourage victims to act quickly without verifying the authenticity of the page.
The phishing operations exploit trusted collaboration platforms, which are essential in hybrid and remote work environments.
As users attempt to join the fake meeting, they receive a warning that their conferencing application is outdated or incompatible. A pop-up instructs them to download and install a "critical update" before joining. This fake update is the attack vector, an executable masquerading as a legitimate software patch.
The attackers exploit business urgency and fear of missing important meetings, leading users to bypass typical security caution. In some cases, the phishing sites include on-screen installation instructions or progress bars to maintain credibility, guiding victims through the setup process of the fake update in a manner consistent with legitimate conferencing tools.
Once executed, the downloaded file installs a legitimate RMM agent such as Datto RMM, LogMeIn, or ScreenConnect. These tools, often pre-approved in enterprise environments, allow remote control, file access, and system management. Because they are digitally signed and legitimate, they can evade antivirus detections and endpoint security controls.
RMM platforms are used to remotely access compromised systems, steal corporate data, move laterally, and, in severe cases, deploy additional payloads such as ransomware. The use of legitimate, trusted software minimizes the chance of detection and provides persistent administrative access without triggering traditional threat detection mechanisms.
Netskope Threat Labs warns that these campaigns highlight how attackers continue to exploit trust in collaboration tools and remote access software. Organizations are advised to monitor the use of RMM tools across their networks, restrict administrative privileges, and educate employees about fake update prompts. IT teams should validate that video conferencing updates come only from official vendor domains and are distributed via secure internal channels.
Based on reporting by GBHackers.
