Week 26: When updates become traps – Malware spreads through fake Zoom invitations

30.06.2026 - In recent weeks, the National Cyber Security Centre (NCSC) has received reports of a scam in which cybercriminals exploit people's trust in video conferencing platforms. Victims are sent invitations to fake Zoom meetings and prompted to download a supposedly necessary update, which in reality contains malware or a remote access tool. Similar scams following the same pattern have also been observed internationally for Microsoft Teams and Google Meet.

It has become much harder in recent years to install malware on a system. Modern operating systems and security tools now flag installation processes and often require users to confirm several steps. Most people will stop the process at that point. As a rule, software can now hardly be installed without some action on the part of the user. Consequently, attackers increasingly try to catch their victims off guard and trick them into doing things they would not normally do. Their aim is to make the situation appear as credible and urgent as possible. The NCSC is currently receiving reports of one typical method that exploits exactly this kind of situation.

A supposed flat enquiry

In one case reported to the NCSC, the scam began on a property portal. A scammer posing as someone interested in a property contacted the person advertising it and suggested discussing the details in a Zoom meeting. The person advertising the property then sent a link to a Zoom meeting. The scammer claimed that the link did not work and sent back what appeared to be a new Zoom link. This link led to a deceptively realistic copy of the official Zoom website, where a pop-up window called for an urgent update. The pop-up was part of the website and had been designed as a "browser-in-the-browser" element, making it look deceptively like a separate browser window. In this case, even the browser address bar was imitated, creating the impression that the target was on the genuine Zoom website. The target was then automatically redirected to another page that imitated the official Microsoft Store, making the supposed update file appear legitimate. They installed the update and, with it, the malware.

A fake business meeting

In the second case described here, the victim received a meeting invitation in their work inbox. When they clicked on the invitation link, a window opened in the browser stating that an update had to be installed before they could join the meeting. Here too, the pop-up window was designed in such a way that the victim believed they were on the correct website. The victim downloaded and ran the file. Notably, the file had a valid digital signature, allowing it to get around conventional signature-based security checks.

Screenshot of an invitation to a purported Zoom meeting containing the alleged update request.
Screenshot of an invitation to a purported Zoom meeting containing the alleged update request.
The supposed Zoom update installs malware.
The supposed Zoom update installs malware.

The supposed updates often conceal software that gives attackers remote access. This can lead to data being stolen, additional malware being downloaded, or ransomware being distributed throughout an organisation.

Why it works

Many people will be familiar with this situation: an online meeting is about to start and you need to join on time. But when you open the invitation link, the software needed to join the meeting either doesn't work or suddenly needs an update. What makes this kind of scam so insidious is that the attackers turn good security habits against their victims. Updating software before using it is, after all, one of the basic rules. Anyone who follows the prompt therefore feels that they are acting particularly responsibly. The pressure of the moment makes this even more effective: the other person is waiting, the meeting is often important for work, and the technical problem needs to be resolved quickly. In this scenario, conventional security advice can also fall short. For example, checking the URL is ineffective when scammers use the "browser-in-the-browser" trick, because the address bar shown on the page is fake. It is not part of the actual browser window, but an image built into the phishing website.

Recommendations

  • Only click on meeting invitations if you are expecting them and know exactly who the sender is.
  • Whenever possible, join virtual meetings directly via the installed program, rather than using a link that has been sent to you.
  • Only download software updates for Zoom, Microsoft Teams or Google Meet via the programs already installed on your device or from the official website. 

Last modification 30.06.2026

Top of page

https://www.ncsc.admin.ch/content/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_26.html