logo

Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload

ID: ebb2073d-bb14-5b53-aa0f-5a8b36ec5f1a

STIX ID: report--ebb2073d-bb14-5b53-aa0f-5a8b36ec5f1a

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-11-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Weaponized Google Meet ClickFix RAT campaign:** A sophisticated social-engineering campaign impersonates Google Meet on gogl-meet.com and instructs users to paste clipboard contents into the Windows Run dialog (Win+R -> Ctrl+V -> Enter), causing a PowerShell-based Remote Access Trojan to execute and bypass browser protections; forensic artifacts (MFT ADS with referrer) confirm infections and defenders are advised to detect PowerShell runs originating from the Run dialog with unusual Unicode or large comment blocks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.