logo

One click on this fake Google Meet update can give attackers control of your PC

ID: c5f820f0-0380-5533-9fd9-32a29983b9ab

STIX ID: report--c5f820f0-0380-5533-9fd9-32a29983b9ab

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

...
...

A phishing page impersonating Google Meet leverages the Windows ms-device-enrollment deep link to silently enroll clicked devices into an attacker-controlled Esper MDM instance, giving the attacker full remote management (software install/removal, system settings, file access, lock/wipe) without deploying malware or stealing credentials. The report includes indicators (updatemeetmicro.online, tnrmuv-api.esper.cloud, Base64-encoded Esper blueprint and group IDs) and recommends checking Settings > Accounts > Access work or school for unknown enrollments, disconnecting suspicious entries, running anti-malware scans, and enforcing MDM enrollment restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.