APT Groups Lure Targets Into Fake Zoom/Teams Meets

AhnLab ASEC · High sophistication
Last updated August 20, 2026

This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of Microsoft’s device-code login flow to steal Microsoft 365 tokens.

How the attack worked

This threat trend report from AhnLab ASEC describes several real-world APT campaigns that rely on social engineering and trusted services rather than purely on malware. In one case, APT38 (BlueNoroff), a North Korea-linked group, used compromised Telegram accounts to lure victims into fake Zoom and Microsoft Teams meetings. Once inside the fake meeting flow, victims were pushed through ClickFix style prompts that executed Windows and macOS malware to steal cryptocurrency wallets and credentials.

A separate cluster of Russia-linked activity focused on Microsoft 365. Attackers compromised Wi-Fi gateways at hotels and conference facilities to exploit DNS poisoning, then abused the Microsoft device-code authentication flow to steal Microsoft 365 credentials and OAuth tokens. A third example involved the group Famous Chollima compromising GitHub maintainer accounts and legitimate repositories, injecting obfuscated JavaScript loaders into npm, Packagist, Go modules, and Chrome extensions to steal credentials and browser data from downstream users.

Why it succeeded

Each scenario leaned on trust in a familiar channel or service: a known Telegram contact, the Microsoft sign-in flow, hotel Wi-Fi, or a widely used open-source repository. The report notes that threat actors are increasingly focusing on exploiting legitimate accounts and services rather than relying solely on malware, which makes these lures harder to distinguish from normal work activity. Executives, finance staff, developers, and frequent travelers were named as primary targets because their roles involve meetings, cloud sign-ins, or code dependencies that make these pretexts plausible.

What to watch for

  • Meeting invites arriving through chat apps like Telegram rather than normal corporate scheduling
  • On-screen instructions during a meeting join that ask you to run commands or scripts (ClickFix-style prompts)
  • Unexpected Microsoft device-code or sign-in prompts, especially on hotel or conference Wi-Fi
  • New code changes or obfuscated scripts appearing in previously trusted repositories or packages

Building resistance

The awareness takeaways emphasize verifying unexpected meeting invites through a separate, known-good channel before joining or following instructions, and training travelers to avoid signing into corporate accounts on untrusted Wi-Fi. Organizations affected span technology, cryptocurrency/fintech, education, manufacturing, and government sectors. The report also recommends prioritizing MFA, separating administrator accounts, integrating log monitoring, and verifying the integrity of open-source and third-party software to reduce exposure to these credential-focused techniques.

Key findings

  • North Korea-linked APT38 (BlueNoroff) used compromised Telegram accounts to lure victims into fake Zoom/Microsoft Teams meetings and used ClickFix to execute malware for credential and crypto wallet theft.
  • Russia-linked activity included credential theft for Microsoft 365 by abusing the Microsoft device-code authentication flow, after compromising Wi‑Fi gateways and using DNS poisoning at hotels/conferences.
  • China-, Iran-, and other region-linked groups emphasized credential theft, persistence, and using legitimate services/tools (webmail, cloud, RMM, developer platforms) to reduce reliance on obvious malware.

Who’s being targeted

  • Commonly targeted roles: Executives, Finance, Developers, DevOps/Engineering, IT/Identity & Access Management, Frequent travelers/remote workers.
  • Affected industries: Technology (software/developers), Cryptocurrency/FinTech, Education (universities), Manufacturing (high-tech manufacturing), Government/Military/Defense.
  • Attack channels: telegram, teams, website, github.
  • Impersonated: A known contact using a compromised Telegram account, Microsoft device-code login flow (abused within a compromised network environment), Legitimate open-source maintainer/repository.

Red flags to watch for

  • Meeting invite comes via an unexpected Telegram message rather than normal corporate scheduling
  • The meeting is "fake" and leads to unusual prompts/instructions (e.g., ClickFix)
  • Pressure to act quickly to join/resolve a meeting issue
  • Logging in to Microsoft 365 via a device-code flow you did not initiate
  • Unexpected sign-in prompts while on hotel or conference Wi‑Fi
  • Sign-in occurs after unusual network behavior (e.g., DNS poisoning)
  • Unexpected obfuscated code added to a previously trusted repository/package
  • New package versions released from a maintainer account showing unusual activity
  • Downstream users report credential/browser data theft after updating
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do attackers use fake Zoom or Microsoft Teams meetings to steal credentials?

APT38 (BlueNoroff) compromised Telegram accounts to send fake Zoom and Microsoft Teams meeting invites, then used ClickFix prompts inside the fake meeting flow to execute malware on Windows and macOS that stole cryptocurrency wallets and credentials.

What is the Microsoft device-code phishing technique described in this report?

Attackers compromised Wi-Fi gateways at hotels and conference facilities to exploit DNS poisoning, then abused the Microsoft device-code authentication flow to conduct credential theft for Microsoft 365 and steal OAuth tokens.

How did a supply-chain attack via GitHub work in this report?

The group Famous Chollima compromised GitHub maintainer accounts and legitimate repositories to inject obfuscated JavaScript loaders into npm, Packagist, Go modules, and Chrome extensions, leading to credential, browser data, and cryptocurrency wallet theft.

What should organizations do to defend against these techniques?

The report recommends prioritizing MFA, separating administrator accounts, integrating log monitoring, and verifying the integrity of open-source and third-party software.

Read the video transcript

APT groups are now using fake Zoom and Teams meetings to steal your passwords and even crypto wallets. APT38, also called BlueNoroff, used compromised Telegram accounts to lure victims into fake Zoom and Microsoft Teams meetings, then ran a tool called ClickFix to install Windows or macOS malware and grab credentials and crypto wallets. Here’s the trap: the invite comes over Telegram instead of your normal calendar, the meeting is just a blank screen with weird ClickFix instructions, or you’re on hotel Wi‑Fi and suddenly see a Microsoft device-code login you never started. If a meeting invite or Microsoft login feels off, stop and verify on a clean channel, call or message the person separately, or open Teams, Zoom, or office.com yourself and check before you click anything.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026