A large phishing campaign is targeting companies worldwide by abusing the trust people place in video conferencing platforms. Researchers at Netskope Threat Labs have observed attackers sending fake meeting invitations for Zoom, Microsoft Teams, and Google Meet to trick employees into installing legitimate remote monitoring and management (RMM) software.Unlike traditional phishing that mainly steals passwords, this campaign aims to gain full administrative control of employee computers. More than 900 organizations have already been affected, especially in education, healthcare, and financial services.

The danger is increased because attackers use real, digitally signed software tools. Since these programs are legitimate and widely used in IT environments, they often bypass standard security controls while giving attackers long-term remote access.

Growing Phishing Success Rates

This campaign appears during a period of rapidly increasing phishing success. Netskope’s 2025 Cloud & Threat Report shows that employees clicked phishing links nearly three times more often in 2024 than in the previous year. Over eight out of every 1,000 users clicked phishing links monthly, representing a 190% increase.
This rise happened even though many companies continue to invest in security awareness training, showing that education alone cannot stop modern phishing tactics.
Cloud applications accounted for more than a quarter of phishing clicks, with Microsoft services being the most commonly impersonated brand. Attackers focus on cloud credentials because they provide access to corporate data and allow further network compromise.

How the Attack Works

Stage 1: Fake Meeting Invitations

The attack begins with emails that look like normal meeting invitations. Attackers often send messages from compromised email accounts, making them appear legitimate.
In some cases, attackers insert malicious links into ongoing email threads that already contain real meeting invitations. Since recipients are already part of the conversation, they are less likely to question the link.
Subject lines usually create urgency, such as tax meetings, team standups, or strategy sessions that appear to require immediate action.

Stage 2: Lookalike Domains

Victims are directed to fake websites using domains that closely resemble real services, such as altered versions of Zoom or Teams domains. Attackers rely on small spelling changes or different domain endings that many users do not notice.
Common tricks include replacing characters with similar ones, adding extra letters, inserting hyphens, or using different domain extensions. Domain abuse is now widespread, with record numbers of disputes related to phishing-related domain registrations.

Stage 3: Realistic Fake Meeting Pages

After clicking the link, victims land on convincing pages that imitate real meeting interfaces. These pages often display fake participant lists and simulated meeting activity, making users believe colleagues are already waiting.
Timers, waiting-room messages, and dynamic participant updates create pressure to join quickly, reducing careful inspection of the page.

Stage 4: Fake Software Update Prompt

When users try to join the meeting, they are told that their conferencing software needs an urgent update. Fake installation screens and progress indicators reinforce the illusion.
This step works well because software updates are common, and employees feel pressure not to delay meetings. Users often bypass security warnings to avoid appearing late or unprofessional.

Stage 5: Installation of Remote Access Software

When the victim downloads the supposed update, they actually install a legitimate RMM tool disguised as meeting software. File names are slightly altered to look authentic.
Commonly abused tools include ConnectWise ScreenConnect, Datto RMM, and LogMeIn Unattended. These tools are widely used in corporate IT environments and allow full remote control, file transfer, and system administration.

Why Attackers Use Legitimate RMM Tools

Using real remote management software gives attackers major advantages compared to custom malware.
Since these tools are digitally signed and trusted, antivirus and endpoint defenses are less likely to block them. Many companies already allow these applications, so their presence does not immediately look suspicious.

RMM platforms also provide powerful features such as remote desktop access, command execution, file transfer, and management of multiple systems. Once installed, the connection can remain active without further user involvement.

If an organization already uses the same tool legitimately, malicious sessions can blend in with normal activity.

What Attackers Do After Access

Once attackers gain remote control, they can perform many harmful actions.
They commonly steal saved credentials from browsers and systems, allowing access to additional corporate accounts. Attackers then move across the network, compromise other systems, and sometimes launch further phishing attacks internally.

Sensitive data is often quietly collected and transferred, including financial records, customer information, intellectual property, and internal communications.
Attackers may also use RMM tools to deploy additional malware across the organization, including ransomware, information stealers, cryptocurrency miners, or hidden backdoors.

RMM Abuse as a Criminal Service

These attacks are now commercially available on underground markets. Ready-to-use attack kits and even pre-compromised network access are sold, lowering the barrier for less-skilled attackers.
Packages often include phishing infrastructure, methods to bypass defenses, persistence features, and tools for stealth operations. Access to compromised networks can be purchased without attackers performing the initial intrusion themselves.

Industries and Regions Most Affected

The campaign affects many sectors, but education, healthcare, and financial services are among the most targeted due to the value of their data and often large user bases.
Most victims are located in the United States, with additional impact seen in Canada, the United Kingdom, and Australia. These regions have widespread remote work and high-value business targets.

Detection and Prevention

For Security Teams

Security teams should closely monitor installations and usage of RMM tools, looking for unauthorized deployments or suspicious connections. Only approved remote management tools should be allowed to run.
Network filtering can help block lookalike domains, while email security should detect suspicious meeting invitations and malicious links. Endpoint detection systems should alert on renamed or suspicious RMM processes and unusual file transfers.

For Organizations

Companies should protect their domains by registering common spelling variations and monitoring newly registered similar domains. Software updates should only be delivered through official IT-managed channels, never through email links.
Security awareness programs should now include training about fake software updates and fraudulent meeting invitations. Incident response plans should specifically address remote management tool abuse.

For Individual Users

Users should avoid clicking unexpected meeting links and instead open meeting platforms directly or use saved bookmarks. Domain names should be checked carefully.
Unexpected software update prompts during meetings should be treated with suspicion. When uncertain, users should contact IT support before installing anything.
Multi-factor authentication should be enabled wherever possible to reduce the damage of stolen credentials.

Broader Security Impact

This campaign shows a shift in attacker strategy. Instead of relying on malware, attackers now abuse trusted software to bypass defenses and maintain access.
By combining fake meeting urgency with update requests, attackers exploit natural workplace behavior and trust in familiar tools. These methods are scalable and easier to monetize through criminal marketplaces.

Recommendations

Fake meeting invitations used to install legitimate remote management tools represent a serious and growing threat. Once installed, attackers gain persistent administrative access that allows data theft, lateral movement, and ransomware deployment.

The sharp increase in phishing success shows that awareness training alone is not enough. Organizations need layered defenses that include domain protection, strong email and web filtering, strict control over RMM tools, modern endpoint detection, and effective incident response.

Security teams must understand that trusted software can become dangerous when controlled by attackers. Monitoring behavior and installation context is now just as important as detecting malware.

As remote collaboration continues to dominate business operations, maintaining vigilance and layered protection remains critical.

Key Takeaways

AI used to code a malwarePhishing success rates have nearly tripled, and fake meeting invites are now widely used to trick employees into installing remote access tools. More than 900 organizations have already been targeted, especially in education, healthcare, and finance.

Attackers rely on legitimate signed software to avoid detection, and underground markets now sell ready-made attack packages. Organizations must combine technical defenses, policy controls, and employee awareness to reduce risk.

Users should independently verify meeting invitations and software update requests, while organizations must strictly control and monitor remote management tools.

References: