
OkoBot Tricks Crypto Users Into Running Commands
Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…
Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected people to malicious archives on file‑sharing services, leading to new malware deployments.
Researchers observed Mirage Kitten running highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa. Two lure types stood out. The first used recruitment-themed content impersonating trusted brands and hiring platforms, drawing targets toward a hiring portal that led to a screening or job-description archive. The second used lookalike videoconferencing pages that appeared to offer a normal meeting join flow but instead redirected victims to malicious archives hosted on third-party file-sharing services. Both paths ended in new malware deployments once the archive was opened.
The campaign relied on highly tailored social engineering lures against selected targets rather than mass, generic messaging. Recruitment pretexts feel routine for HR staff and hiring managers, so an unexpected screening pack does not automatically read as suspicious. Meeting invites carry similar authority, since employees are conditioned to click links to join calls quickly. Hosting final payloads on third-party file-sharing services also let the attackers avoid relying on infrastructure that looked obviously malicious at first glance, making the download step blend in with legitimate business file transfers.
Organizations in aerospace, defense, telecom, government, and financial services, the sectors named in this activity, should treat recruitment and meeting-related file downloads as a distinct risk category. Practical steps include verifying unexpected recruiting outreach through known, trusted contact channels before opening any attachment, and training staff to recognize that a meeting link redirecting to a file download is not standard behavior for common videoconferencing tools. Because these lures relied on highly tailored details, awareness programs should emphasize that personalization is not proof of legitimacy. Reinforcing consistent verification habits, regardless of how convincing or specific a message appears, reduces the chance that a single well-crafted lure leads to malware execution across an organization.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Mirage Kitten is an espionage-focused threat group that ran highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa.
Attackers sent recruitment-themed messages impersonating trusted brands and hiring platforms, directing targets to portals that led to malicious archive downloads hosted on third-party file-sharing services.
Lookalike videoconferencing pages redirected victims away from a normal meeting flow toward malicious archives hosted on third-party file-sharing services, ultimately deploying malware.
The lures were highly tailored to specific individuals and roles, which made them appear more credible even though personalization does not indicate legitimacy.
You get an email: “Interview screening materials for your application.” Looks legit, big-name brand logo, tailored right to your role. Behind the scenes, this is Mirage Kitten: highly targeted spear‑phishing using fake recruitment portals and lookalike meeting pages that push malware archives from file‑sharing sites. Here’s the trap: the email says hiring portal, but the link quietly sends you to an odd domain or a fake video‑conferencing page, which then redirects again to a .zip on a random file‑sharing site. Your move: if a recruiting email or meeting link wants you to download a .zip, stop, don’t open it, forward it to security and confirm the request through a known, trusted contact.

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…