Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload
ID: ebb2073d-bb14-5b53-aa0f-5a8b36ec5f1a
STIX ID: report--ebb2073d-bb14-5b53-aa0f-5a8b36ec5f1a
Feed Name: cybersecurityNews.com
**Weaponized Google Meet ClickFix RAT campaign:** A sophisticated social-engineering campaign impersonates Google Meet on gogl-meet.com and instructs users to paste clipboard contents into the Windows Run dialog (Win+R -> Ctrl+V -> Enter), causing a PowerShell-based Remote Access Trojan to execute and bypass browser protections; forensic artifacts (MFT ADS with referrer) confirm infections and defenders are advised to detect PowerShell runs originating from the Run dialog with unusual Unicode or large comment blocks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
