Cybersecurity Reach Foundation
← All safety alerts
confirmedBrand: Zoom

Fake Zoom invite pushes a Microsoft Store lookalike and suspicious installer

A page hosted in an Amazon S3 bucket presents a fake Zoom meeting invitation. It imitates a Microsoft Store listing for Zoom Workplace, claims that an update or plug-in is required, and starts a download. The download points to a ScreenConnect client installer hosted on a separate domain. Treat the installer as unsafe and do not open it.

A fake Microsoft Store page displays Zoom Workplace with an Install button and Microsoft branding.
This page imitates the Microsoft Store and offers a Zoom installer. Do not install software offered by an unexpected meeting invite.

Observed domain or link

  • zoom-meet-us997234[.]s3[.]us-east-2[.]amazonaws[.]com
  • pivotalequipmentllc2[.]screenconnect[.]com

What to do

  • Do not open the invite or install the offered plug-in or update.
  • If the file was downloaded, do not open it. Delete it and empty the recycle bin or trash.
  • Run a security scan using your device's trusted security software.
  • If you entered a password, change it from a separate trusted device and turn on multi-factor authentication.
  • Report the message to the service or organization it impersonates.

What this alert does not establish

  • The landing page was reviewed without executing the downloaded installer.
  • The page content observed shows a fake Microsoft Store presentation and a download-started message; this record does not claim independent malware analysis of the MSI file.
  • The hosting and download URLs may change or stop responding.

Share this warning

This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.

Observed:
Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.