logo

ClickFix tactic: The Phantom Meet

ID: a5e342fb-d0b4-5e44-965a-cdb107451af2

STIX ID: report--a5e342fb-d0b4-5e44-965a-cdb107451af2

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2024-10-17

Date Updated: 2026-04-29

Author: Quentin Bourgue and Sekoia TDR

...
...

Sekoia.io TDR details the emerging ClickFix social-engineering tactic—fake browser error prompts that coax users into copying and executing malicious commands—and gives a chronological and technical analysis of a Google Meet–impersonating cluster that distributes Windows and macOS infostealers (Stealc, Rhadamanthys, AMOS), documents associated infrastructure and IoCs, and links operations to traffer teams ‘Slavic Nation Empire (SNE)’ and ‘Scamquerteo’.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.