Criminals are impersonating journalists, investors, podcast hosts, and business contacts on Zoom, then pressuring targets to share their entire screen and approve remote control. Once access is granted, attackers may install malware and steal passwords, browser sessions, cryptocurrency, files, and social-media accounts.
This is generally a social-engineering attack abusing a legitimate Zoom feature—not evidence that Zoom’s servers were hacked. The safest rule is simple: never give an unsolicited caller remote control of your computer.
The short version
The best-documented campaign, associated with ELUSIVE COMET and also referred to in reporting about Aureon Capital, follows a carefully staged pattern:
- An attacker approaches a high-value target through social media or a professional-looking booking process.
- The attacker impersonates a journalist, investor, podcast host, recruiter, or media organization.
- During a Zoom call, the attacker claims the target cannot be seen or heard and asks for full-screen sharing.
- After screen sharing begins, the attacker requests remote control.
- The victim may see a participant labeled “Zoom”, creating the false impression that the request is official.
- With control approved, the attacker can operate the computer and attempt to install malware or steal information.
Security Alliance and Malwarebytes document this pattern in their Zoom hardening guidance and reporting on the campaign.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How the Zoom remote-access scam works
1. The attacker chooses a valuable target
Targets may have public visibility, cryptocurrency holdings, business authority, access to corporate systems, or valuable online accounts. Cryptocurrency holders, executives, influencers, journalists, investors, and founders are especially attractive because one compromised computer can expose both money and credentials.
2. The attacker builds credibility
Contact may begin on X or another social network. The account may contain convincing posts, videos, followers, or an apparently legitimate history. The attacker may also use a professional scheduling service such as Calendly.
A polished profile or booking page is not independent verification. Confirm the invitation using a known email address, telephone number, or official website—not only the account or link that initiated contact.
3. The call creates technical pressure
The attacker may keep their camera off and claim that the meeting is malfunctioning. Common excuses include:
- “I cannot see your presentation.”
- “Your camera or microphone is not working.”
- “You need to share your entire desktop.”
- “I need to control your screen to fix the problem.”
The goal is to make an unusual request feel like routine troubleshooting. Urgency and confusion reduce the chance that the victim stops to verify what is happening.
4. Full-screen sharing exposes information
Sharing the entire desktop can reveal password-manager windows, wallet applications, browser tabs, notifications, email, recovery codes, private documents, and clipboard contents. It may also show enough information for an attacker to target the victim’s contacts later.
Sharing one application window is safer than sharing the desktop, but it is not risk-free. The visible application may contain secrets, and the attacker may continue pressuring the victim to change the sharing mode.
5. The attacker requests remote control
Zoom’s remote-control feature can allow another participant to interact with the shared computer after the user approves the request. In the documented campaign, the attacker reportedly used the display name “Zoom” to make the prompt appear authoritative.
Free tools Windows power users keep installed
One-click scans. No signup required.
Participant names are user-controlled labels. A participant called “Zoom” is not proof that the request came from Zoom. Treat it as a warning sign.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
6. Access can lead to theft
After approval, the attacker may operate the computer as the user, subject to the operating system’s permissions and the meeting’s conditions. The attacker may try to install malware, access browser sessions, copy files, view credentials, or manipulate financial and cryptocurrency accounts.
Malwarebytes reported that Jake Gallen of Emblem Vault said malware called goopdate was installed during such a call. Gallen reported that more than $100,000 in Bitcoin and Ethereum was stolen and that the attackers accessed his X, Gmail, and other accounts. That amount is his reported account, not an independently audited loss figure.
Is this a Zoom hack?
Usually, no. The documented ELUSIVE COMET incidents primarily relied on impersonation, urgency, screen sharing, and the victim’s approval of remote control. They do not, by themselves, show that Zoom’s infrastructure was breached or that an attacker gained access without user interaction.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →That makes this different from:
- A vulnerability that permits unauthorized access without the victim approving anything.
- A compromised Zoom server or customer database.
- Zoombombing, where an unwanted participant disrupts a meeting.
- A fake Zoom installer delivered through a phishing page.
- A conventional remote-support scam.
“Zoom attack” describes the delivery channel and abused feature. It does not necessarily mean Zoom itself was technically compromised. Zoom’s security-bulletin archive covers separate client and Contact Center vulnerabilities; those should not automatically be conflated with this social-engineering campaign.
What attackers may be able to steal
Remote control does not guarantee that every category below was taken in every incident. It creates an opportunity to access information that is visible, unlocked, stored locally, or available through active sessions.
- Cryptocurrency wallet interfaces, private keys, seed phrases, and signing workflows.
- Unlocked password-manager vaults.
- Browser cookies and active login sessions.
- Email, social-media, exchange, banking, and cloud accounts.
- Local files, backups, screenshots, and clipboard contents.
- Authentication codes displayed on screen.
- Corporate documents and internal systems.
- Contacts who may later receive convincing messages from a hijacked account.
A hardware wallet can reduce exposure of private keys, but it does not protect exchange passwords, email accounts, browser sessions, social-media accounts, or users who approve malicious transactions. Never sign a transaction under pressure during a meeting.
Warning signs to screenshot
- An unsolicited invitation from a journalist, investor, recruiter, podcast host, or business partner.
- Pressure to act quickly or remain on the call while making security or account changes.
- Refusal to verify identity through a separate, known channel.
- A meeting organizer whose identity cannot be independently confirmed.
- A claim that the other party cannot see or hear you unless you share the entire screen.
- A request to share the whole desktop instead of one specific application.
- An unexpected remote-control prompt during an ordinary call.
- A participant named “Zoom” or another supposedly official service account.
- A request to grant Zoom accessibility permissions on macOS.
- A demand to download an update, codec, transcript viewer, plug-in, or security tool.
- A Windows
.exeor.msi, or a macOS package, delivered through chat, email, or a fake waiting room. - A download hosted on a domain that is not Zoom’s official website.
The decisive rule: a routine interview or business meeting should not require an unknown participant to control your computer.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsHow to protect yourself before joining
Verify the invitation independently
Contact the supposed journalist, company, investor, or organizer through a known address or phone number. Find contact information independently rather than using only the social-media profile, direct message, or booking link supplied by the stranger.
Use the browser when practical
Security Alliance recommends joining through the Zoom web client at zoom.us/join where possible. Its guidance says the browser client does not provide the same remote-control capability as the desktop client.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Browser features may be more limited, and availability can depend on the meeting configuration and Zoom’s current behavior. This is a risk-reduction measure, not a guarantee of safety.
Use a low-risk device
Do not join a suspicious meeting from the computer that stores cryptocurrency wallets, password-manager access, corporate credentials, sensitive documents, or valuable browser sessions. A separate, updated device containing minimal personal data limits the damage if you make a mistake.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteInstall software only through trusted channels
Get Zoom from the official Zoom website, your device’s official app store, or an organization-managed software channel. Never install a remote-access utility because a stranger says it is required for audio, video, screen sharing, or an update.
What to do during the call
- Reject unexpected remote control. Do not approve the request, even if the participant name appears to be “Zoom.”
- Stop screen sharing immediately if the other party asks for control.
- Leave the meeting instead of debating or troubleshooting with the caller.
- Do not share the entire desktop. If sharing is genuinely necessary, select only a specific window.
- Close sensitive applications first: wallets, password managers, email, banking and exchange pages, recovery codes, private documents, unrelated browser tabs, and notifications.
- Reject requests for accessibility permissions, administrator approval, browser extensions, remote-management agents, and unknown downloads.
Zoom settings organizations can review
Security Alliance documents these paths in the Zoom web portal:
Zoom web portal → Settings → Meeting → In Meeting (Basic) → Remote control → Off
It also recommends:
Settings → Meeting → In Meeting (Basic) → Screen sharing → Who can share? → Host Only
Exact labels and available controls can vary by account type, administrator policy, Zoom version, and future interface changes. Organizations should review settings centrally and reinforce them with user training. Technical controls cannot prevent an employee from trusting an impersonator outside the meeting.
If you approved remote control or installed software
Assume that both the device and accounts visible during the session may be at risk. Prioritize containment over trying to investigate the attacker yourself.
1. Disconnect the affected computer
Disable Wi-Fi and unplug Ethernet. Stop communicating with the attacker. Do not continue the meeting while attempting to remove software.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2. Use a clean device
From a different, trusted computer or phone, change passwords beginning with:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →- Email accounts.
- Your password manager.
- Cryptocurrency exchanges and custodians.
- Banking and payment accounts.
- Social-media accounts.
- Cloud and work accounts.
Use unique passwords and enable strong multifactor authentication where available.
3. Revoke sessions and authorizations
Sign out of all active sessions, remove unknown devices, and review connected applications. Revoke exposed API keys, wallet connections, browser sessions, recovery codes, and other credentials that may have been visible or accessible.
4. Protect financial and cryptocurrency assets
Contact banks, exchanges, custodians, and payment providers immediately. If private keys or seed phrases may have been exposed, move remaining assets to a newly secured wallet created on a clean device. Do not send money to anyone promising paid “fund recovery”; victims of cryptocurrency theft are frequently targeted by follow-on recovery scams.
5. Preserve evidence
Save direct messages, emails, invitations, domains, installer names, timestamps, screenshots, wallet addresses, transaction IDs, and account alerts. Avoid wiping the only copy of evidence before consulting qualified incident-response personnel.
Recommended Free Tools
6. Consider rebuilding the device
If an attacker had interactive control and installed software, deleting one visible application may not remove persistence. A professional assessment or secure operating-system rebuild is safer than assuming the computer is clean. A clean antivirus result does not prove that exposed sessions, credentials, or private keys are safe.
7. Involve your organization
Business users should notify IT or security staff, rotate credentials, review endpoint alerts, and check for attempted movement into other systems. Executives and people managing valuable digital assets should consider professional incident response with credential-theft and cryptocurrency expertise.
8. Report the abuse
Use Zoom’s abuse-reporting guidance. Also report financial fraud to the relevant bank, exchange, payment provider, law-enforcement agency, or consumer-protection authority. For cryptocurrency theft, preserve blockchain transaction details and report them promptly to the affected exchange and appropriate authorities. The SEAL incident-response playbook provides incident-specific guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A related but different threat: fake Zoom updates
Not every Zoom-themed scam uses the live meeting’s remote-control feature. A separate pattern uses fake invitations, counterfeit waiting rooms, or phishing pages to display a supposed “Zoom update required” message.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
The downloaded package may install malware or a legitimate remote-monitoring product abused without authorization. Malwarebytes documented a 2026 campaign involving unauthorized use of Teramind, a commercial monitoring product. Teramind said it was not affiliated with the attackers and condemned unauthorized misuse. That reporting does not establish that Teramind is inherently malicious.
Switzerland’s National Cyber Security Centre has also reported fake Zoom invitations leading to malware or remote-access-tool downloads, with similar tactics involving Microsoft Teams and Google Meet.
These variants share impersonation and pressure, but they are technically different:
| Pattern | What the victim does | Main risk |
|---|---|---|
| Remote-control scam | Shares the screen and approves a control request | Interactive access to the computer and exposed information |
| Fake-update scam | Downloads and runs a supposed meeting update | Malware or unauthorized remote-monitoring software |
Legitimate Zoom updates can exist, but unsolicited updates delivered through chat, email, or a counterfeit meeting page are high-risk. Obtain software only through trusted official channels.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Common objections—and why they do not eliminate the risk
“I only shared my screen.”
Anything visible may have been exposed, including credentials, wallet activity, recovery codes, private messages, and personal information. Review and rotate anything shown during the session.
“The caller looked legitimate.”
Attackers can build convincing profiles, use professional scheduling services, and maintain long-running accounts. Independent verification is stronger than follower counts, polished branding, or a booking page.
“I joined from my phone.”
This may reduce the risk of desktop malware installation, but it does not eliminate phishing, credential theft, social engineering, or disclosure of sensitive information. An attacker may pressure you to switch to a computer.
“I use a hardware wallet.”
A hardware wallet helps protect private keys, but it does not protect exchange credentials, email, social accounts, browser sessions, or transactions you approve under pressure.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11“My antivirus found nothing.”
Remote-access tools can be legitimate software misused by an attacker, and account theft may occur through exposed sessions or credentials rather than a conventional malware file. Interactive compromise may require session revocation, professional investigation, or rebuilding the device.
What security products can—and cannot—do
Endpoint protection, managed device controls, and incident-response services can be useful layers, especially for businesses and high-value targets. They are not substitutes for refusing unexpected remote control.
Quick Recap
- Zoom Workplace provides the platform and administrative controls, but paying for a higher tier does not stop impersonation or user-approved access.
- Malwarebytes can support endpoint scanning and protection, but a scan cannot undo stolen sessions, exposed private keys, or unauthorized transactions.
- Microsoft Defender for Endpoint is aimed primarily at managed business environments and requires appropriate deployment and investigation.
- Microsoft Intune and Jamf can help organizations restrict software installation and enforce device policies, but they do not replace security awareness.
- Professional incident response may be appropriate after confirmed interactive compromise, particularly for businesses, executives, crypto firms, and victims with valuable systems. Avoid unsolicited “recovery agents” demanding upfront cryptocurrency payments.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




