Zoom Update Scam Infects 1,437 Users in 12 Days to Deploy Surveillance Tools
A recent cybersecurity incident has been identified where malicious actors are targeting Windows users through fraudulent Zoom meeting invitations. Over a span of twelve days, 1,437 users inadvertently installed a harmful version of the Teramind…
A recent cybersecurity incident has been identified where malicious actors are targeting Windows users through fraudulent Zoom meeting invitations. Over a span of twelve days, 1,437 users inadvertently installed a harmful version of the Teramind monitoring agent, initiated by a deceptive Zoom meeting page designed to trigger automatic downloads.
The operation utilizes the domain uswebzoomus[.]com/zoom/ , which mimics the authentic Zoom interface. Upon accessing, users are presented with a counterfeit waiting room replicating Zoom's standard display. Artificial participants named “Matthew Karlsson,” “James Whitmore,” and “Sarah Chen” appear in the call, with realistic audio effects enhancing the deception.
The fraudulent site displays a continuous “Network Issue” warning, creating an expectation of a required update. This visual misdirection primes users to accept a subsequent fake update. Interaction from the user, such as clicking or typing, activates the scam, bypassing automated security systems.
Shortly after engaging with the site, users encounter an “Update Available” prompt with an unavoidable five-second countdown. Upon completion, a file named zoom_agent_x64_s-i(__941afee582cc71135202939296679e229dd7cced).msi is automatically downloaded. Concurrently, the site redirects to a page resembling the Microsoft Store, falsely indicating the installation of “Zoom Workplace.”
Security experts have confirmed that the installer contains internal labels such as “Agent version 26.3.3403” and “Server IP or host name,” linking it to a pre-configured Teramind agent managed by attackers. This agent installs under the disguise of dwm.exe in the hidden directory C:\ProgramData{GUID} , operating in stealth mode to evade detection.
A recent cybersecurity incident has been identified where malicious actors are targeting Windows users through fraudulent Zoom meeting invitations.
Users who suspect interaction with this fraudulent site should take the following steps:
Do not execute the downloaded MSI file. Check C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A} for any suspicious activity. Run sc query tsvchst in Command Prompt (as administrator) to verify if the agent is active. Change passwords using a secure device and seek IT assistance for further resolution.
This incident underscores the misuse of legitimate monitoring tools for malicious purposes. It highlights the importance of accessing video conferencing platforms directly via their official websites, rather than through unsolicited links, to avoid security breaches.
Indicator Type Value
File Hash (SHA-256) 644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa
Domain uswebzoomus[.]com
Teramind Instance ID 941afee582cc71135202939296679e229dd7cced
Based on reporting by GBHackers.
