
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked Android remote-access tool (RAT) framework called “Flying Eagle.” The tooling lets criminals build convincing look‑alike apps and then steal credentials through in-app “overlay” login prompts targeting payment, banking, and government service apps.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
You see a site saying, “Download the official Provincial Public Security Bureau service app” for Android. Looks like a real police portal, right? Behind that APK could be the Flying Eagle Android RAT. Criminals use it to build fake police and welfare apps, complete with copied icons and text, all controlled from one of over 170 known servers. Once installed, it can pop up perfect-looking overlays on top of your banking or payment apps. You think you’re logging into your bank, but you’re handing credentials straight to their Night Dragon successor. Your move: if an 'official' app comes as an APK download link, skip it. Only install government or banking apps from the official app store with the verified publisher name.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…