Cybercriminals Use Fake Zoom, Teams Calls to Deliver Malware
ID: db948657-78a3-5cf8-8b2e-6092fcd25c62
STIX ID: report--db948657-78a3-5cf8-8b2e-6092fcd25c62
Feed Name: GBHackers
SEAL observed a DPRK-linked UNC1069 campaign (Feb–Apr 2026) that uses hijacked or impersonated professional chats and staged Zoom/Teams lookalike meetings to socially engineer crypto professionals and developers into running AppleScript files or terminal commands that retrieve modular malware; the malware (macOS-primary, also Windows/Linux) performs credential and key theft, persistence, C2 communication, and lateral movement, and SEAL has blocked 164 associated domains while noting a related npm supply-chain link.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
