Cybersecurity Reach Foundation
← All safety alerts
investigatingBrand: Zoom

Fake Zoom meeting page downloads malware

A page at quickmeetinglink[.]es copies Zoom branding and claims that the latest Zoom Workplace app is required to join a meeting. It directs visitors to download a file before continuing. The downloaded file was flagged as malware. Close the page, delete the file, and open Zoom through its official app or website instead.

A fake Zoom page says the latest Zoom Workplace app is required and tells visitors to download it before joining a meeting
A fake meeting page copies Zoom and pushes a malware download. Do not install software from an unexpected meeting link.

Observed domain or link

  • quickmeetinglink[.]es
  • quickmeetinglink[.]es/esjoinzoom[.]us/Windows/invite[.]php

What to do

  • Do not download or run the offered file.
  • Close the page and join Zoom through the official app or by typing the official website address yourself.
  • If you downloaded the file but did not run it, delete it and empty the Trash or Recycle Bin.
  • If you ran it, disconnect the device from the internet and ask a trusted technician or security professional for help. Change important passwords from a different clean device.

What this alert does not establish

  • The page operator and number of people targeted were not confirmed. The downloaded file was flagged as malware; do not execute or redistribute it.

Share this warning

This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.

Observed:
Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.