chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
""
Netskope One AI Security
Le aziende hanno bisogno di un’AI sicura per far crescere il proprio business, ma i controlli e i guardrail non devono richiedere sacrifici in termini di velocità o esperienza d’uso.Netskope ti aiuta a dire di sì a tutti i vantaggi dell'AI.
""
Netskope One AI Security
Le aziende hanno bisogno di un’AI sicura per far crescere il proprio business, ma i controlli e i guardrail non devono richiedere sacrifici in termini di velocità o esperienza d’uso.Netskope ti aiuta a dire di sì a tutti i vantaggi dell'AI.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures

Feb 12 2026

Summary

Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications, including Zoom, Microsoft Teams, and Google Meet. The attackers trick corporate users to execute the payload by claiming a mandatory software update is required to join the video call, redirecting victims to typo-squatted domains, such as zoom-meet.us.

The payload, disguised as a software update, is a digitally signed remote monitoring and management (RMM) tool such as Datto RMM, LogMeIn, or ScreenConnect. These tools enable attackers to remotely access victims’ machines and gain full administrative control over their endpoints, potentially leading to data theft or the deployment of more destructive malware.

Key findings

  • Phishing campaigns leverage the high-trust environment of corporate communication by mimicking Google Meet, Microsoft Teams, and Zoom landing pages. These decoys exploit the victim’s urgency to join a scheduled call, leading them to a pixel-perfect phishing page.
  • Attackers prompt victims to install mandatory software updates to join the video conference call leading to the download of the payload.
  • Attackers deploy digitally signed RMM agents—including Datto RMM, LogMeIn, and ScreenConnect—to gain administrative remote access. By leveraging legitimate software, they can bypass the need for custom malware that might trigger security controls.

The bait: Video conference invite as phishing lure

Netskope Threat Labs is currently tracking multiple phishing campaigns that leverage video conference call invitations as lures. In these campaigns, attackers impersonate well-known videoconferencing applications such as Zoom, Microsoft Teams, and Google Meet. To increase credibility, the phishing pages closely mimic legitimate pages, often displaying lists of participants who have “joined” the call. As victims attempt to join, they may see additional participants appear, further enhancing the illusion of authenticity.

The hook: Software update trap

As victims attempt to join the call, they are presented with a notification indicating that their application is out of date or incompatible. To proceed, victims must download and execute a provided “update” before being allowed to join. By framing the malicious payload as a critical technical fix for a legitimate business task, attackers increase the likelihood that users will manually bypass security warnings in order to avoid missing the session.

Some phishing sites even provide steps on how to “install” the software update, as shown in the image below.

The payload: Digitally signed RMM agents

Once the victim agrees to the “software update,” they download a digitally signed executable or MSI installer. To maintain the deception, these binaries are renamed to match the expected platform, using names like GoogleMeeet.exe or ZoomWorkspaceinstallersetup.msi. From the phishing campaigns Netskope Threat Labs investigated, we identified LogMeIn Unattended, Datto, and ScreenConnect as the primary RMM agents used as payloads. By deploying legitimate, digitally signed RMM tools rather than custom malware, the attackers can blend in with standard corporate traffic. These tools can be pre-approved in enterprise environments, allowing the attackers to bypass signature-based security controls and gain a persistent administrative foothold without raising immediate alarms.

Once attackers gain privileged access, they have a wide array of post-exploitation options at their disposal. By leveraging the native, legitimate features of these RMM agents—such as file transfer, remote shell, and screen sharing—they can silently collect sensitive information or move laterally through the victim’s network to identify high-value targets. Most critically, because these tools are designed for mass software deployment, attackers can use the RMM’s own infrastructure to push more potent malware across the entire environment with ease, turning a single compromised endpoint into a full-scale corporate breach.

Conclusions

Netskope Threat Labs is monitoring an active phishing campaign that exploits the high-frequency nature of virtual meetings. By weaponizing fake video conference invites as a primary lure, attackers leverage the “mandatory software update” as a powerful psychological hook to coerce users into executing malicious payloads. This sophisticated chain of events leads to the deployment of legitimate, digitally signed remote monitoring and management (RMM) tools. By gaining this administrative foothold, attackers bypass traditional security filters and secure a persistent platform for severe post-exploit actions, ranging from sensitive data collection to the mass delivery of ransomware.

author image
Jan Michael Alcantara
Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Jan Michael Alcantara is an experienced incident responder with a background on forensics, threat hunting, and incident analysis.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.