
Fake Zoom/Teams Calls Used to Steal Crypto Wallets
North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent could run on a schedule, take "TASK" instructions via email, and exfiltrate results back to the attacker.
This attack, referred to as "AgentForger," began with a single link that looked like an ordinary invitation to open a ChatGPT productivity template. The link embedded a malicious prompt directly in its URL parameters. If the recipient was already logged into ChatGPT, clicking the link opened the Agent Builder in their authenticated session and automatically submitted the embedded prompt, no further clicks or approvals required. From there, the prompt instructed ChatGPT to create a new agent, attach the victim's already-authorized connectors (such as email, Drive, Slack, or Teams), and set every connector's approval setting to "Never ask."
The technique worked because it relied entirely on conditions that already existed in a normal workday: an employee logged into ChatGPT Workspace with connected business apps. There was no separate credential theft step needed to plant the agent, since the attack rode on the victim's existing session and permissions. Once published, the attacker made the agent persistent by scheduling it to run every hour, and the agent used inbound emails with a "TASK" subject line as a channel for ongoing remote instructions, sending results back to the attacker automatically.
Organizations using ChatGPT Workspace or Enterprise features should train employees, especially executives, executive assistants, operations, and finance staff, to treat unexpected agent-builder links as high-risk and to verify them before clicking, particularly while already logged in. Because the rogue agent could also impersonate the victim on Microsoft Teams to send further phishing links leading to a fake Microsoft login page, reinforcing Teams-based phishing awareness across all employees is equally important. Regularly reviewing connected agents, their connector permissions, and any scheduled automation can help catch this kind of silent persistence before it leads to broader business email compromise scenarios.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The link embedded a malicious prompt in the URL to ChatGPT's Agent Builder. If the victim was already logged in, ChatGPT opened the Builder in their authenticated session and auto-submitted the prompt without any further interaction.
The malicious prompt configured the agent to publish and schedule itself to run every hour, turning the initial click into a persistence mechanism inside the victim's connected apps.
Attackers emailed the victim's mailbox with a subject line starting with "TASK"; the agent checked for these emails during each run, executed the instructions, and emailed results back to the attacker.
Yes, the rogue agent could impersonate the victim to send phishing links on Microsoft Teams to coworkers, redirecting them to a fake Microsoft login page to steal credentials.
You get an email: “Quick operating brief, open in ChatGPT.” Link looks legit: chatgpt.com… so you click. Behind the scenes, that one click opens ChatGPT Agent Builder in your logged-in session and auto-submits a hidden prompt in the URL to forge a “chief-of-staff” agent in your Workspace. The rogue agent silently hooks into Outlook, Drive, Slack, Teams, flips connectors to “Never ask,” publishes itself, and runs every hour, reading TASK emails and emailing results back out like a hidden coworker. Your move: if a ChatGPT link opens Agent Builder or you see connectors set to “Never ask” and agents you don’t remember creating, stop and report it to Security immediately.

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…