Fake Google Meet invitation, fake Microsoft Store, real malware attack · Blog · Sublime Security
ID: 25f63f08-68bf-581b-a446-296206fa7701
STIX ID: report--25f63f08-68bf-581b-a446-296206fa7701
Feed Name: Sublime Security Blog
This Attack Spotlight details a phishing campaign that impersonates Google Meet (via the lookalike domain googglemeetinglnterviiew.live) and a fake Microsoft Store page to trick victims into downloading an MSI (GoogleMeet_agent_x64_... .msi, SHA256 ba19a101eb250064b986d9e2c2ba0d9ab668c3d1a37bac3f41424dc9e902fa12) which installs Teramind remote monitoring software to grant attackers remote control and sends execution notifications over Telegram; the report includes detection signals and recommended defensive approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
