
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and abuse of Microsoft Teams as growing entry points, with many incidents progressing into deeper intrusion.
Threat intelligence covering the legal sector found that adversary-in-the-middle (AiTM) phishing has become the most common way attackers gain initial access to law firms, responsible for 28.57% of initial access events. Instead of simply stealing a password, AiTM pages proxy the real authentication flow. A user enters credentials and completes an MFA prompt as normal, but the attacker sits in the middle of that exchange and captures the resulting session cookie, gaining access without ever needing to defeat MFA directly.
A second common pattern used fake browser or portal errors, often called ClickFix-style lures, where a message claims a document viewer, e-filing system, or court portal needs urgent attention. These errors were elevated in legal incidents (13.39%) compared to cross-industry rates (8.77%), and the technique primarily delivered a remote access trojan when victims followed the on-screen 'fix' steps.
These attacks succeeded by exploiting two things at once: technical trust in MFA and human urgency. Because the login flow looks legitimate and MFA is genuinely completed, users have little reason to suspect anything is wrong. Layered on top of that, deadline pressure specific to legal work, such as court filings, made staff more likely to act quickly on an unexpected error rather than pause to verify it. Microsoft Teams abuse was also noted as a growing entry point, appearing in 6.25% of cases, nearly double the cross-industry figure.
Because 86% of observed incidents progressed beyond initial access into active intrusion, with ransomware intrusion at 23%, stopping AiTM phishing at the entry point matters. Recommended defenses include deploying phishing-resistant MFA such as FIDO2 keys and passkeys, adopting conditional access policies that evaluate device health and location, and monitoring identity platform logs for anomalous session activity. Staff should also be trained to verify document portal or court filing issues through a known bookmark or official channel rather than following in-page prompts, especially under deadline pressure.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
AiTM (adversary-in-the-middle) phishing proxies the real login process, so even when a user enters correct credentials and completes an MFA challenge, the attacker captures a valid session cookie and can access the account without needing the password or MFA code again.
A legal-sector threat intel report found AiTM phishing was the most common initial access method in the legal sector, accounting for 28.57% of initial access events, often using deadline-driven lures tied to court filings and document portals.
Tycoon2FA is a phishing-as-a-service platform that was attributed as driving 52.3% of AiTM-related account compromises in the legal sector across 2025.
In 86% of observed incidents, activity progressed beyond initial access into active intrusion, and ransomware intrusion occurred in 23% of cases.
In law firms right now, the number one break‑in method isn’t malware, it’s AiTM phishing that steals your session even after MFA. Here’s the trick: you click an email link, land on a perfect-looking login, enter your password, even approve MFA, and an AiTM service like Tycoon2FA quietly grabs your session cookie and walks into your account as you. Or you’re racing a filing deadline, and a fake court portal or document viewer throws a ‘ClickFix’ error, “you must install this to view the filing”, which quietly drops NetSupportManager RAT while you think you’re just clearing a blocker. Your move: if a login or portal error pops up from a link, email, Teams, wherever, don’t trust it. Close it, then go to your own bookmark or type the official site yourself and sign in there.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…