Fake Zoom Downloader is the Latest Method of Attack on Remote Workers

Stu Sjouwerman | May 7, 2020

iStock-1218651188Riding on the coattails of the massive rise in popularity in the video conference solution, remote workers new to Zoom need to be wary of where they download the installer.

We’ve written before about the various types of Zoom-related attacks that have sprouted up over the last two months. The latest chapter in this saga involves an actual Zoom installer laden with backdoor malware. Available on malicious third-party sites (and not from Zoom’s official website), these installers are offered up using phishing emails and spam campaigns designed to direct potential victims to these alternative installers.

The compromised installer does deliver an installation of Zoom, but also installs the remote access trojan (RAT) WebMonitor, giving attackers remote access to an infected endpoint via a web browser.

This kind of attack isn’t new, but the rise in necessity and popularity of video conferencing solutions makes Zoom the perfect brand to leverage.

To avoid becoming a victim, the simple answer here is to train users to do two things:

  • Don’t act on unsolicited emails about software updates, even if they seem pertinent.
  • Only download software from the official website, if at all. 

Users undergoing Security Awareness Training already understand the importance of these two simple best practices. But with so many other types of attacks that seek to trick users into participating, it’s important for users to be continually educated to ensure they don’t make these small understandable mistakes with huge ramifications.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.