This threat trend report describes multiple real-world APT campaigns where attackers rely on social engineering and trusted services (Zoom/Teams, Telegram, webmail, GitHub) to steal credentials and access cloud accounts. Notable examples include fake meeting lures to deliver malware, and abuse of Microsoft’s device-code login flow to steal Microsoft 365 tokens.
How the attack worked
This threat trend report from AhnLab ASEC describes several real-world APT campaigns that rely on social engineering and trusted services rather than purely on malware. In one case, APT38 (BlueNoroff), a North Korea-linked group, used compromised Telegram accounts to lure victims into fake Zoom and Microsoft Teams meetings. Once inside the fake meeting flow, victims were pushed through ClickFix style prompts that executed Windows and macOS malware to steal cryptocurrency wallets and credentials.
A separate cluster of Russia-linked activity focused on Microsoft 365. Attackers compromised Wi-Fi gateways at hotels and conference facilities to exploit DNS poisoning, then abused the Microsoft device-code authentication flow to steal Microsoft 365 credentials and OAuth tokens. A third example involved the group Famous Chollima compromising GitHub maintainer accounts and legitimate repositories, injecting obfuscated JavaScript loaders into npm, Packagist, Go modules, and Chrome extensions to steal credentials and browser data from downstream users.
Why it succeeded
Each scenario leaned on trust in a familiar channel or service: a known Telegram contact, the Microsoft sign-in flow, hotel Wi-Fi, or a widely used open-source repository. The report notes that threat actors are increasingly focusing on exploiting legitimate accounts and services rather than relying solely on malware, which makes these lures harder to distinguish from normal work activity. Executives, finance staff, developers, and frequent travelers were named as primary targets because their roles involve meetings, cloud sign-ins, or code dependencies that make these pretexts plausible.
What to watch for
- Meeting invites arriving through chat apps like Telegram rather than normal corporate scheduling
- On-screen instructions during a meeting join that ask you to run commands or scripts (ClickFix-style prompts)
- Unexpected Microsoft device-code or sign-in prompts, especially on hotel or conference Wi-Fi
- New code changes or obfuscated scripts appearing in previously trusted repositories or packages
Building resistance
The awareness takeaways emphasize verifying unexpected meeting invites through a separate, known-good channel before joining or following instructions, and training travelers to avoid signing into corporate accounts on untrusted Wi-Fi. Organizations affected span technology, cryptocurrency/fintech, education, manufacturing, and government sectors. The report also recommends prioritizing MFA, separating administrator accounts, integrating log monitoring, and verifying the integrity of open-source and third-party software to reduce exposure to these credential-focused techniques.
Key findings
- North Korea-linked APT38 (BlueNoroff) used compromised Telegram accounts to lure victims into fake Zoom/Microsoft Teams meetings and used ClickFix to execute malware for credential and crypto wallet theft.
- Russia-linked activity included credential theft for Microsoft 365 by abusing the Microsoft device-code authentication flow, after compromising Wi‑Fi gateways and using DNS poisoning at hotels/conferences.
- China-, Iran-, and other region-linked groups emphasized credential theft, persistence, and using legitimate services/tools (webmail, cloud, RMM, developer platforms) to reduce reliance on obvious malware.
Who’s being targeted
- Commonly targeted roles: Executives, Finance, Developers, DevOps/Engineering, IT/Identity & Access Management, Frequent travelers/remote workers.
- Affected industries: Technology (software/developers), Cryptocurrency/FinTech, Education (universities), Manufacturing (high-tech manufacturing), Government/Military/Defense.
- Attack channels: telegram, teams, website, github.
- Impersonated: A known contact using a compromised Telegram account, Microsoft device-code login flow (abused within a compromised network environment), Legitimate open-source maintainer/repository.
Red flags to watch for
- Meeting invite comes via an unexpected Telegram message rather than normal corporate scheduling
- The meeting is "fake" and leads to unusual prompts/instructions (e.g., ClickFix)
- Pressure to act quickly to join/resolve a meeting issue
- Logging in to Microsoft 365 via a device-code flow you did not initiate
- Unexpected sign-in prompts while on hotel or conference Wi‑Fi
- Sign-in occurs after unusual network behavior (e.g., DNS poisoning)
- Unexpected obfuscated code added to a previously trusted repository/package
- New package versions released from a maintainer account showing unusual activity
- Downstream users report credential/browser data theft after updating
Frequently asked questions
How do attackers use fake Zoom or Microsoft Teams meetings to steal credentials?
APT38 (BlueNoroff) compromised Telegram accounts to send fake Zoom and Microsoft Teams meeting invites, then used ClickFix prompts inside the fake meeting flow to execute malware on Windows and macOS that stole cryptocurrency wallets and credentials.
What is the Microsoft device-code phishing technique described in this report?
Attackers compromised Wi-Fi gateways at hotels and conference facilities to exploit DNS poisoning, then abused the Microsoft device-code authentication flow to conduct credential theft for Microsoft 365 and steal OAuth tokens.
How did a supply-chain attack via GitHub work in this report?
The group Famous Chollima compromised GitHub maintainer accounts and legitimate repositories to inject obfuscated JavaScript loaders into npm, Packagist, Go modules, and Chrome extensions, leading to credential, browser data, and cryptocurrency wallet theft.
What should organizations do to defend against these techniques?
The report recommends prioritizing MFA, separating administrator accounts, integrating log monitoring, and verifying the integrity of open-source and third-party software.
Read the video transcript
APT groups are now using fake Zoom and Teams meetings to steal your passwords and even crypto wallets. APT38, also called BlueNoroff, used compromised Telegram accounts to lure victims into fake Zoom and Microsoft Teams meetings, then ran a tool called ClickFix to install Windows or macOS malware and grab credentials and crypto wallets. Here’s the trap: the invite comes over Telegram instead of your normal calendar, the meeting is just a blank screen with weird ClickFix instructions, or you’re on hotel Wi‑Fi and suddenly see a Microsoft device-code login you never started. If a meeting invite or Microsoft login feels off, stop and verify on a clean channel, call or message the person separately, or open Teams, Zoom, or office.com yourself and check before you click anything.