Threat actors used fake installers for Zoom and Microsoft Teams to compromise users seeking collaboration software, often through cloned download pages and malicious ads. In one Zoom campaign, a trojanized ZoomPortable.exe established persistence through the Windows Startup folder, unpacked a modified Zoom client into a temporary directory, and later used a patched zoom.exe to fetch and run a PowerShell payload that profiled victims, contacted attacker-controlled infrastructure, and accepted reconnaissance and arbitrary execution commands. Investigators observed follow-on activity including shellcode linked to Cobalt Strike, while Microsoft separately reported FakeUpdates malvertising that redirected victims to fake Teams update sites, installed legitimate software as cover, and delivered malware including ZLoader, Predator the Thief, NJRat/Bladabindi, and Cobalt Strike beacons.

Get the infrastructure and lures behind it.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft Defender for Endpoint alerted on suspicious PowerShell execution initiated by a Zoom process on a customer workstation on April 7, 2021. Investigation showed the Zoom instance was running from a temp-directory installation created by a malicious self-extracting file named ZoomPortable.exe.
In May, researchers found malware samples masquerading as Zoom installers, including Trojan.Win32.ZAPIZ.A and Backdoor.Win32.DEVILSHADOW.THEAABO. These fake installers also deployed a legitimate Zoom client to reduce user suspicion.
In April, researchers discovered attacks that bundled a legitimate Zoom installer with the RevCode WebMonitor RAT, identified as Backdoor.Win32.REVCODE.THDBABO. The malware provided remote command execution, file manipulation, keystroke logging, and information-gathering capabilities.
Talos reported that attackers used Discord CDN links in 2020 malspam campaigns to distribute malicious archives and payloads, including Formbook and Nymaim. The lures commonly impersonated invoices, shipping documents, and other business communications.
Microsoft reported that in 2020 the FakeUpdates malvertising campaigns were dropping WastedLocker ransomware. The campaigns used fake software update lures and continued evolving their payloads and delivery methods.
Microsoft said the FakeUpdates malvertising campaigns had previously been observed in 2019 delivering DoppelPaymer ransomware. This established an earlier lineage for the later fake software update and collaboration-app lures.
Analysis showed the fake Zoom installer persisted via the Startup folder, unpacked a modified Zoom client into the temp directory, and used a patched zoom.exe to download and execute b.ps1 after a delay of two to seven days. The PowerShell payload profiled victims, accepted reconnaissance and arbitrary execution commands, and in at least one case fetched shellcode that Microsoft Defender detected as Cobalt Strike.
Investigators determined the malicious ZoomPortable.exe was downloaded via Chrome from veehy[.]com, a cloned Zoom download site, after the victim followed a path consistent with a Google advertisement click through linkx[.]ind[.]br. The user later confirmed the delivery vector was a Google ad for Zoom.
Cisco Talos published analysis showing threat actors increasingly used Discord and Slack for malware hosting, second-stage retrieval, command-and-control, and data exfiltration. The report documented multiple malware families and webhook-based exfiltration techniques abusing legitimate collaboration infrastructure.
Trend Micro described cybercriminal campaigns abusing popular communication platforms, including fake Zoom installers, Slack webhook reporting by Crypren ransomware, and Discord-hosted malware delivery leading to AveMaria or AgentTesla infections. The report highlighted how attackers blended malicious activity with trusted collaboration services.
Microsoft warned customers about FakeUpdates campaigns that used malicious ads and poisoned search results for Microsoft Teams to redirect victims to attacker-controlled domains. The infections installed legitimate Teams software as cover while delivering malware such as Predator the Thief, ZLoader, NJRat, and Cobalt Strike, with some attacks ending in ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
blog.trendmicro.com
Open sourceinde.nz
Open sourceblog.talosintelligence.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.