Teramind is a legitimate employee monitoring and remote monitoring/management tool that has been repurposed by threat actors for unauthorized remote access and covert surveillance. Reporting in the provided content links it to FakeMeeting/ClickFix phishing campaigns impersonating Google Meet, Zoom, DocuSign, and Paperless Post, where victims are lured through fake meeting or document pages, shown fake update prompts and fake Microsoft Store pages, and ultimately delivered a Teramind MSI installer, including ZIP-delivered payloads such as GoogleMeetInstaller.zip. The installer has been observed delivered from attacker-controlled paths such as /download.php and /Windows/download.php. In one campaign, the final-stage binary was identified as Teramind remote monitoring software repurposed as commodity RAT-like malware.
The observed Windows MSI payloads were legitimate Teramind installers reused across multiple lures. Researchers verified Zoom- and Google Meet-themed MSI samples were byte-for-byte identical, with MD5 AD0A22E393E9289DEAC0D8D95D8118B5 and SHA-256 644ef9f5eea1d6a2bc39a62627ee3c7114a14e7050bafab8a76b9aa8069425fa. The MSI uses a .NET custom action, Teramind.Setup.Actions.CustomActions.ReadPropertiesFromMsiName, to parse the installer filename and extract a 40-character hex instance identifier from the s-i(__...) portion of the filename, allowing one binary to be configured for different attacker-controlled Teramind instances. Observed instance identifiers include 941afee582cc71135202939296679e229dd7cced and 06a23f815bc471c82aed60b60910b8ec1162844d.
Behaviorally, the installer defaults to stealth mode with TMSTEALTH=1, performs a preflight connectivity check to rt.teramind.co, and aborts if it cannot connect unless TMSKIPSRVCHECK is used. It exposes configuration properties including TMINSTANCE, TMROUTER, TMENCRYPTION, SOCKS5 proxy settings, and TMHTTPPROXY. After installation, it creates persistent Windows services 'tsvchst' (svc.exe) and 'pmon' (pmon.exe), both running as LocalSystem with restart-on-failure behavior. DNS queries to rt.teramind.co begin within seconds and recur roughly every 11 seconds. Additional artifacts noted for detection include kernel drivers tm_filter.sys and tmfsdrv2.sys and a fixed ProgramData GUID directory {4CEC2908-5CE4-48F0-A717-8FC833D8017A}.
The content also notes Teramind abuse in other intrusion contexts. ASEC reported that in Trigona-linked MS-SQL server compromises, the actor likely used Teramind in addition to RDP and AnyDesk for control of infected systems, with a Bat2Exe-generated downloader attempting to install an external MSI presumed to be Teramind. Separately, Cofense reported Teramind as one of the few legitimate remote access tools abused in Italian-language phishing campaigns. Teramind stated it was not affiliated with the threat actors, did not deploy the software, and condemned the unauthorized abuse of monitoring technologies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Stage 4 /download.php — auto-download GoogleMeetInstaller.zip (hidden iframe, 1.5s delay)
"Once the monitoring agent is installed and running, the installer will delete the temporary files and folders it created and used."
"The attackers did not write custom malware. They deployed a professionally developed commercial product..."
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate commercial employee monitoring / remote monitoring software repurposed by the phishing campaign as a remote access tool after victims are lured through fake Google Meet, Zoom, and DocuSign pages.
Legalne komercyjne oprogramowanie do monitoringu pracowników nadużyte jako narzędzie nieuprawnionego nadzoru. W opisywanej kampanii jest dostarczane jako MSI podszywający się pod aktualizacje Zoom/Google Meet, konfiguruje identyfikator instancji (TMINSTANCE) na podstawie nazwy pliku, instaluje się w trybie ukrytym, zakłada trwałe usługi (m.in. tsvchst i pmon), ładuje sterowniki filtrów jądra (tm_filter.sys, tmfsdrv2.sys) i natychmiast rozpoczyna komunikację z infrastrukturą Teramind (domyślnie rt.teramind.co).
Commercial monitoring/RMM tooling suspected to be installed via an MSI fetched by a batch downloader, used to maintain remote control/visibility on compromised systems.
Legitimate monitoring/remote tool abused as a RAT in Italian-language campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.