Threat Actors Weaponize Fake Microsoft Teams Domains to Target Users
ID: 79ae9770-af3c-595f-9973-7b800b49a927
STIX ID: report--79ae9770-af3c-595f-9973-7b800b49a927
Feed Name: GBHackers
UNC1069, a DPRK-linked financially motivated threat actor, is operating a social-engineering campaign that uses a fake Microsoft Teams domain (onlivemeet.com) to host convincing meeting pages which prompt victims to download a malicious update (RAT). The actors leverage revived conversations from compromised Telegram and LinkedIn accounts, Slack impersonation, and pre-scheduled meetings via legitimate services like Calendly to increase credibility; defenders are advised to verify destination URLs and treat unexpected meeting/update requests with caution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
