Hackers are using fake Zoom installer apps to trick users into downloading the hostile BlackSuit ransomware that takes over systems and steals data.
Researchers at DFIR have found that the attack is being initiated through a fraudulent Zoom installer. This installer deceives unsuspecting users into downloading malware from a convincing replica of Zoom’s website.
Windows users are at risk of infection from BlackSuit ransomware, a well-documented cyber threat that has previously targeted schools, healthcare organisations, and other essential services. Once the malicious software infiltrates a system, it remains inactive for several days, evading immediate detection.
When triggered, it executes a coordinated assault, extracting sensitive data, encrypting critical files, and issuing a ransom demand to restore access.
More Specifics on How the Malware Works
The BlackSuit ransomware attack begins with a fraudulent website, zoommanager[.]com, impersonating Zoom to trick users into downloading a malicious loader. Once installed, the malware disables Windows Defender, remains undetected, and retrieves further payloads via a Steam Community page.
To evade suspicion, it downloads both a genuine Zoom installer and malicious software, then injects itself into MSBuild.exe, a trusted Microsoft process. After eight days of dormancy, it activates, gathering system data, deploying Cobalt Strike for lateral movement, and installing QDoor for remote access.
Finally, it exfiltrates critical data before unleashing BlackSuit ransomware, which encrypts files and demands payment.
The History of the BlackSuit Ransomware
The BlackSuit ransomware gang emerged in early 2023 and quickly gained notoriety for targeting healthcare, education, and other critical sectors.
In early 2024, it attacked South Carolina’s Kershaw County School District (KCSD), claiming to have stolen 17GB of sensitive data. In June 2024, BlackSuit was linked to a crippling ransomware attack on CDK Global, forcing US car dealerships to revert to manual operations. Reports suggest CDK paid the ransom to restore services.
That same month, the gang targeted the Kansas City Police Department (KCKPD). When the department refused to pay, BlackSuit leaked highly sensitive law enforcement data, including payroll records, homicide crime scene photos, and fingerprint databases.
BlackSuit also allegedly breached Kansas City Hospice, a nonprofit providing end-of-life care, adding it to its victim list on October 19th, according to Cybernews’ Ransomlooker monitoring tool.
What Lessons Can IT Leaders Learn From This Threat?
The BlackSuit ransomware campaign highlights the evolving sophistication of cyber threats and the devastating impact on critical sectors. IT leaders can take a proactive, multi-layered approach to cybersecurity to mitigate risks and enhance resilience.
Strict software verification is essential. The attack leveraged a fake Zoom installer, emphasising the need for zero-trust policies and app allowlisting to prevent unauthorised software execution. Endpoint detection and response (EDR) solutions can also pinpoint unusual activity before malware takes hold.




