
Hackers are exploiting various applications , such as Zoom, to infect systems with malware. Security from Trend Micro have discovered two malware samples that infect Windows systems and present themselves as Zoom installers. The malicious Zoom installers are not distributed through official distribution channels.
Fake Zoom installers
One of these fake Zoom installers installs a backdoor that allows attackers to gain remote access Windows computer the victim's. The second is the Devil Shadow botnet.
The first malicious installer looks very similar to the official version. It contains encrypted files that will decrypt the malware version.

The malware "kills" the current remote utilities upon installation and opens TCP port 5650 to gain remote access to the infected system.

In addition, it runs an official zoom installer so as not to arouse suspicion.
The second fake Zoom installer is related to the Devil Shadow Botnet. The infection begins with the malicious installer, with a file called pyclient.cmd that contains malicious commands.
And in this case, hackers include a copy of the official Zoom installer to trick victims. The compromised app installer deploys a malicious archive and code.
The malware sends its C&C collected information every 30 seconds when the computer is turned on. More details about the fake installers can be found here.
In another hacking campaign, attackers used fake Zoom installers to infect victims with the WebMonitor RAT. The infection begins with the download of the malicious ZoomIntsaller.exe from malicious sources.
Due to the coronavirus pandemic, many companies around the world have asked employees to work from home. This new situation has increased the use of video conferencing applications, which has not gone unnoticed by cybercriminals.
However, there are some signs that something is wrong. For example, the above Zoom installers are hosted on suspicious sites and not on official app stores, such as the Play Store, App Store, or Zoom’s download center. Another sign is that the malicious installers install and run the “legitimate Zoom installer” more slowly than the real program. The malicious versions take longer to execute, as they extract the malicious components before Zoom runs.
