Fake Zoom and Google Meet scams install Teramind: A technical deep dive
2026-03-04T21:17:54Z•040c7f5623ecac937c43e1030f2fb6bdb9660723a379acccca365a216a5cdbff
TeramindValleyRATcard‑skimmingcredential‑theftdata‑exposurefake‑updatesmalicious‑adsmonitoring‑softwarephishingprivacyscamssocial engineeringsurveillancewarethird‑party‑breachvendor‑misconfiguration
What happened
Malwarebytes reported multiple active phishing and scam campaigns that abuse trusted brands and legitimate tooling to deliver surveillance and credential‑stealing malware. Notable incidents include fake Zoom/Google Meet pages that trigger bogus “updates” to silently install Teramind (abused as surveillanceware), a fake Huorong site distributing ValleyRAT, Facebook ads pushing fake Windows 11 downloads that steal passwords and crypto wallets, and an Avast refund impersonation that harvests full credit‑card details. Coverage also highlights third‑party breaches and data exposures (Conduent, Best
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 040c7f5623ecac937c43e1030f2fb6bdb9660723a379acccca365a216a5cdbff
- Enrichment time
- 2026-03-04T21:17:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.