Organizations Beware: Requests for Assistance Prompting Malicious Zoom Extension Downloads

Public and private sector organizations post available services on their websites and online platforms. They may also provide referrals and offer an online search feature to find local assistance. Threat actors exploit this feature to send supposed requests for assistance and trick their targets into installing malicious browser extensions and malware. They request a further discussion of services and initiate a fake meeting invitation, prompting targets to click a link and download a purportedly necessary extension to join the meeting. Instead, the targets download malicious installers or extensions from spoofed video teleconferencing (VTC) websites. If executed, threat actors can install remote monitoring and management (RMM) tools, infostealers, ransomware, and more.

The NJCCIC received a report of threat actors conducting reconnaissance on a New Jersey public-sector website and exploiting its local assistance search feature to pose as a potential client and target a New Jersey organization. Like previous requests, the target organization received what appeared to be a legitimate request for assistance. The threat actors stated they had several questions and wanted to discuss the services further via a Zoom meeting.

The threat actors initiated a Zoom meeting invitation that contained a link (hxxps://meetlive[.]es/joinzoom[.]us) but did not provide a dial-in phone number. To appear authentic, the email included screenshots showing how to download and add the Zoom extension, and advised enabling the microphone and camera. The email instructed the target to open the link on a laptop or desktop, rather than a mobile device that may have strict security policies or rules limiting full remote takeover capabilities. When the link was clicked, it prompted the target to download a Zoom extension, even though Zoom was already installed on the target’s device.

The email thread further revealed that the target organization sent a Zoom meeting invite. However, the threat actors claimed that the link did not work because their computer was old and attempted to convince the target organization to use their link instead. Organizations that receive VTC meeting requests, such as Zoom, initiated by potential clients should proceed with caution.

Recommendations

  • Exercise caution with communications from unknown contacts and clicking links or attachments.
  • Create VTC meeting links via official portals to send to potential clients.
  • Enable multi-factor authentication (MFA) and keep systems and browsers up to date.
  • If victimized, disconnect from the internet and run anti-virus/anti-malware scans.

If sensitive information was entered, change passwords for compromised accounts, monitor for unauthorized activity, and review the Identity Theft and Compromised PII NJCCIC Informational Report for additional recommendations and resources.

Report malicious cyber activity to the NJCCIC and the FBI’s IC3.

This was published in the NJCCIC Weekly bulletin for July 23, 2026.