
OkoBot Tricks Crypto Users Into Running Commands
Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…
AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious extension that later enabled theft of about $630,000 in crypto.
This incident began with a trusted relationship rather than a cold phishing attempt. The attacker used a Telegram account belonging to a real industry contact the victim had met at a conference, and that account had been compromised. The message asked to schedule a routine catch-up call and included what looked like a Microsoft Teams meeting link.
When the employee joined the call, the link mimicked Microsoft Teams but had no working audio. That friction set up the next step: the victim's computer almost immediately prompted them to update Microsoft Teams. Believing it was a normal fix for the audio issue, they approved the update, which installed a malicious browser extension instead of a legitimate patch.
Several factors combined to make this scenario convincing:
Defenders and employees should be alert to a few specific signals drawn from this case:
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The attacker used a Telegram account belonging to a real conference contact that had been compromised, then reached out to schedule a routine catch-up call, exploiting an existing relationship.
After joining a call link that mimicked Microsoft Teams and experiencing no working audio, the victim was prompted to update Microsoft Teams and approved the procedure, which installed a malicious extension.
It captured keyboard input, clipboard history, screenshots, and browsing history, and could swap crypto wallet addresses.
According to the reporting, the attacker remained resident and quietly collected data for almost a month before draining wallets.
Imagine losing six hundred thirty thousand dollars because you clicked one fake Microsoft Teams link from a contact you trust. In this real case, a North Korea–linked group hijacked a conference contact’s Telegram, sent a fake Teams meeting link, and when the call had no audio, a pop-up instantly demanded a Microsoft Teams update. Approving that fake update secretly installed a malicious extension that logged keystrokes, grabbed screenshots and browsing history, and quietly watched for nearly a month before draining their crypto wallets. If a meeting link from chat suddenly triggers a Teams "update," stop. Do not run it, close it and report it to IT immediately so we can check your device.

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Researchers found a macOS info‑stealing malware, CrashStealer, delivered through a signed and Apple‑notarized installer so it looks legitimate and passes…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…