Share
THREAT REPORT - MEETING-APP IMPERSONATION

The Zoom meeting that installs spyware: the fake "update" scam of 2026

You click a meeting link, a Zoom or Teams window seems to load, other names appear in the participant list, and then a message says your app is out of date and needs an update to continue. The people in that room are not real, and the update is not an update. It is a signed installer that hands your computer to someone else.

SafeBrowz Threat Research Security ResearchAugust 5, 20269 min read

A real meeting app never updates from a web page mid-call.

If a pop-up during a Zoom, Microsoft Teams or Google Meet meeting tells you to download and install an update to join or continue, it is a malware scam. Close the tab. Genuine updates come from the app you already have or from the official app store, never from a page you were sent to. The download in this scam is not a video app, it is a remote-access or monitoring tool. In one case documented by Malwarebytes it installed Teramind, a stealth monitoring tool that logs keystrokes and takes screenshots. The one rule that never fails: you never have to install anything to join a meeting.

SafeBrowz checks the meeting or update link before the page can push a download. Add to Chrome, free Get the free Android app or scan a URL now →

The meeting that was never real

Malwarebytes pulled one of these pages apart in early 2026, and the choreography is worth seeing because every step is designed to lower your guard before the download. The victim opens a link and lands on a page dressed up as a Zoom call. A waiting room loads with scripted participants, names like Matthew Karlsson and Sarah Chen sitting in the list as if the meeting is about to start. Looping audio and a hardcoded "Network Issue" banner prime you to expect that something needs fixing.

About ten seconds in, an "Update Available" pop-up appears with a five second countdown and no way to close it. While a fake Microsoft Store screen fills the background, the browser quietly downloads an installer. The file is named to look like Zoom's own software, and what it actually installs is Teramind, a legitimate employee-monitoring product switched into stealth mode. From that point it records keystrokes, captures screenshots at intervals, and logs which sites and apps you open. The domain in that campaign, defanged, was uswebzoomus[.]com, a typosquat of the real zoom.us.

Nothing on that page is what it claims to be. The participants are images, the audio is a loop, the "store" is a picture, and the update is spyware. The only genuinely interactive thing on the screen is the button that infects you.

Why "your app is out of date" is the whole trick

Strip away the theatre and this is a single lie repeated across every version of the scam: to keep using this thing you already trust, install this small thing right now. It works because updating software is a normal, healthy habit, and the attacker has borrowed the feeling of doing the responsible thing.

But the premise is false. Zoom, Teams and Google Meet do not stop a meeting to make you fetch an update from a web page. If the desktop app genuinely needs updating, it updates itself, or you get it from the Microsoft Store, the Mac App Store, or the vendor's own site that you typed in. A meeting page has no business handing you an executable. Once you hold that line, the entire scam falls apart, no matter how convincing the fake waiting room looks.

The corporate version: signed remote-control tools

Consumers get spyware. Businesses get something built for deeper access. Through 2026, Microsoft's Defender researchers and the security firm Netskope tracked a parallel wave aimed at company employees, using the same fake-meeting shell but a heavier payload. Instead of a monitoring app, the "update" installs a remote monitoring and management tool, the kind IT teams legitimately use to administer machines, such as ScreenConnect or LogMeIn. Once it is running, the attacker has hands-on-keyboard control: they can see the screen, move files, run commands, and use that foothold to move across the network or drop ransomware.

The detail that makes this dangerous is the signature. Attackers have been abusing legitimate code-signing certificates so the malicious installer is digitally signed, and the operating system raises no warning when it runs. A valid signature used to be a reasonable trust signal. In these campaigns it is not, because the certificate belongs to a real company and was misused. That is why the defence cannot be "does it look signed", it has to be "did my own app ask for this update, or did a web page".

A live example of this corporate strain, defanged, is zoom-meet[.]us, a typosquat that dresses itself as a Zoom meeting host. Both of the domains named in this post are flagged as dangerous by our scanner, so if you or a colleague paste one in, you get a clear warning rather than a download.

How you get the link in the first place

The invite rarely looks like spam, and that is the point. Three routes show up again and again in 2026 reports:

  • A hijacked real account. The message comes from a colleague or contact whose account was already compromised, so it arrives from a name you trust with no obvious red flag.
  • The platform switch. A "client" or "recruiter" books a call, then messages a few minutes before to say the original tool is not working and sends a replacement link, often moving you from Zoom to a Teams link they control. The switch is the tell, because it puts you on a page they chose.
  • A calendar or email invite that looks routine, with a join button that points at a lookalike domain rather than zoom.us, teams.microsoft.com or meet.google.com.

In all three the sender feels safe, which is exactly why the advice has to be about the destination. This is the same lesson as the crypto-targeted fake meeting-link malware scam, where a trusted DM leads to a booby-trapped call, and the deepfake Zoom call fraud, where the faces on screen are synthetic. Judge the page, never the person who sent it.

Block the fake update page before the download

SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus a free Android app on Google Play. This scam lives at one clickable moment: the fake meeting or update link opening in your browser. That is a URL, and it is exactly what our 3-layer engine checks. Layer 1 inspects the link locally, Layer 2 cross-references the domain server-side against our 550+ brand database plus the Google Safe Browsing, PhishTank and URLhaus feeds and our own blocklist, and Layer 3 reads the page. The AI deep scan (Premium, $14.99/year) reads pages in over 100 languages, which is what catches a lookalike meeting host registered this week. Honest scope: we check the page you are sent to, not a file already saved to your machine, so if an installer has run it is your antivirus that has to clean up. The page is where we stop it.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

The 30-second check before you click join

  • Look at the domain, not the logo. A real meeting is on zoom.us, teams.microsoft.com or meet.google.com. Anything else wearing those names, like a hyphenated or padded lookalike, is fake.
  • You never install to join. Zoom, Teams and Meet all run in the browser or in the app you already have. A page that requires a download is the scam, full stop.
  • Ignore the countdown. The five second timer and the "meeting is starting" pressure exist to stop you thinking. A real meeting waits for you.
  • Treat a platform switch as a warning. If someone moves you from the agreed tool to a fresh link at the last minute, open the original tool yourself and rejoin from there.
  • A signature is not safety. "It is signed, so Windows trusted it" is exactly the false comfort these campaigns rely on.

If you already ran the installer

Speed matters, because these tools are built to give someone else control quietly.

  • Disconnect the device from the internet to cut off the remote session, then leave it off the network until it is cleaned.
  • Run a full scan with reputable antivirus. This is the part SafeBrowz cannot do for you: a link checker stops you reaching the page, but a file already on disk is an antivirus job. On a work machine, contact your IT or security team immediately rather than cleaning it yourself, because they need to know an RMM tool may be installed.
  • Change your passwords from a different, clean device, starting with email, and turn on two-factor authentication everywhere. Anything you typed while the tool was running should be treated as seen.
  • Report it. In the US, file at reportfraud.ftc.gov and, if money or company data was lost, at the FBI's ic3.gov. In the UK, report to Action Fraud. If it hit a work device, your security team should treat it as a potential intrusion, not just a virus.
  • Watch for the follow-up. Our guide to what to do in the first 24 hours after a scam covers the recovery-fraud that often arrives next.

Detection signatures come from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Not sure about a meeting or "update" link?

Paste it here before you open it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

A pop-up during my Zoom meeting said an update is available. Is it real?

No. Zoom, Microsoft Teams and Google Meet never make you download an update from a web page in the middle of a call. Genuine updates come from the installed app itself or from the official app store, never from a meeting page. A countdown timer, a fake "participants are waiting" screen, or a button that downloads a file is the scam. Close the tab, open the app you already have, and rejoin from there.

The meeting link came from a real client or colleague. Doesn't that make it safe?

Not on its own. In 2026 many of these invites come from real accounts that were already compromised, or from an attacker who moved the conversation to a new platform ("Zoom is not working, here is a Teams link instead"). The friendly source is part of the trick. Judge the page you land on, not who sent it. If it asks you to install anything to join, it is fake.

What actually gets installed if I click the update?

It varies by campaign, but it is always a remote-access or spying tool, not a video app. Malwarebytes documented a fake Zoom page that installed Teramind, a commercial monitoring tool set to stealth mode that logs keystrokes and takes screenshots. A separate 2026 wave flagged by Microsoft Defender and Netskope dropped signed remote-management tools such as ScreenConnect or LogMeIn, giving the attacker full control of the computer. The installer is often named to look like the real app, for example something ending in msi that copies the app's own filename.

The download was digitally signed, so my computer trusted it. How?

Attackers have been buying or stealing legitimate code-signing certificates so their malware is signed and the operating system does not warn you. Researchers traced one 2026 campaign to a certificate issued to a real company that was abused for this. A valid signature is no longer proof a download is safe. The only safe update is the one your installed app fetches for itself.

Can SafeBrowz stop this scam?

It stops the page, not the file. SafeBrowz is a browser extension and Android app that checks links and pages, so it works at the moment the fake meeting or update link opens in your browser. Its 3-layer engine checks the address against a blocklist and a 550+ brand database, then reads the page, and flags a typosquat like the ones in this scam before you reach the download. What it cannot do is scan a file already saved to your computer, so if an installer has run, that is a job for your antivirus. The rule that always works: never install anything to join a meeting.

Last updated 2026-08-05

Related SafeBrowz coverage

Follow on Google