logo

Threat Actors Weaponize Fake Microsoft Teams Domains to Target Users

ID: 79ae9770-af3c-595f-9973-7b800b49a927

STIX ID: report--79ae9770-af3c-595f-9973-7b800b49a927

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Divya

...
...

UNC1069, a DPRK-linked financially motivated threat actor, is operating a social-engineering campaign that uses a fake Microsoft Teams domain (onlivemeet.com) to host convincing meeting pages which prompt victims to download a malicious update (RAT). The actors leverage revived conversations from compromised Telegram and LinkedIn accounts, Slack impersonation, and pre-scheduled meetings via legitimate services like Calendly to increase credibility; defenders are advised to verify destination URLs and treat unexpected meeting/update requests with caution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.