
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and breach/security notifications) to trick targets into clicking links, opening files, or installing malicious packages. It highlights how attackers increasingly abuse trusted platforms (GitHub, Google Docs/Drive, npm, LinkedIn, Telegram, and cloud storage) to deliver malware or steal accounts and tokens.
This threat trend report describes several unrelated APT campaigns that share a common thread: social engineering delivered through everyday professional channels rather than obvious spam. Attackers posed as recruiters on LinkedIn, requested code reviews or issued fake security advisories to developers, and built phishing pages that mimicked a widely used email service. Once a target clicked a link, opened a file, or signed into a spoofed page, the attackers moved to credential theft, remote access, or data exfiltration.
Each lure was built around an activity people do routinely at work. A developer reviewing code, a job seeker responding to a recruiter, or an employee logging into email are all normal actions, which makes the malicious version harder to spot at a glance. The report notes that North Korea linked actors exploited developer-friendly platforms such as GitHub, npm, VS Code, and Cursor, blending malicious content into tools developers already trust. Iran-linked Nimbus Manticore used fake LinkedIn recruiters and impersonated a real job portal, Ebix, adding a layer of apparent legitimacy to the outreach.
Organizations across software development, cryptocurrency and financial services, government, defense, healthcare, energy, and telecommunications are all named as affected industries, showing how broadly these lures can reach. Developers and DevOps staff should verify code-review or advisory requests through a trusted channel before authenticating anywhere or running referenced code. HR, finance, and general staff should treat unexpected recruiter outreach and "security update" prompts with the same scrutiny as any unsolicited request for credentials. Because legitimate cloud services such as GitHub Releases, Google Drive, Dropbox, and pCloud were used for C2 communication and payload delivery, security teams should assume these platforms can be abused and build verification steps around any shared file or link, not just around unfamiliar domains. Techniques referenced in this report include spearphishing links (attack.mitre.org/techniques/T1566/002), spearphishing attachments (attack.mitre.org/techniques/T1566/001), and trusted relationship abuse (attack.mitre.org/techniques/T1199).
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Recent campaigns rely on job offers and fake recruiters, code review or security advisory requests, and phishing pages disguised as legitimate email services, according to the report.
North Korea linked actors have exploited developer-friendly platforms such as GitHub, npm, VS Code, and GitLab, using social lures like job offers and code reviews to reach developers and crypto professionals.
Nimbus Manticore lured victims using fake LinkedIn recruiters and by impersonating the Ebix job portal, then deployed data exfiltration and remote control capabilities.
Since legitimate cloud services such as GitHub Releases, Google Drive, Dropbox, and pCloud have been used for command and control and payload delivery, employees should confirm the sender and business reason before opening any shared file or link.
You get a LinkedIn message: “Hi, I’m recruiting for a role that matches your background. Please apply via the Ebix job portal link below.” Looks legit, right? Iran-linked Nimbus Manticore used fake LinkedIn recruiters and an Ebix lookalike site to get people to click, then deployed data theft and remote control tools, straight from that “job application” flow. Same playbook hits developers too: email says, “Subject: Code review request, please check this repo change ASAP.” You click a GitHub link, it wants you to sign in again or run a new package, perfect spot for North Korea–linked actors to steal tokens or slip in malicious code. Here’s the move: if a recruiter or code review request comes out of the blue and pushes a specific link, don’t click it, open the site yourself in a fresh tab and verify the job or repo from there.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…