← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Beware: Fake Google Meet Pages Deliver Infostealers in Ongoing ClickFix Campaign
Threat actors are using fake Google Meet web pages as part of the ClickFix campaign to deliver infostealers targeting Windows and macOS systems. The attackers display fake error messages in web browsers, tricking users into executing malicious PowerShell code. The campaign has expanded to impersonate various online services, including Facebook, Google Chrome, and reCAPTCHA. On Windows, the attack deploys StealC and Rhadamanthys stealers, while macOS users are targeted with the Atomic stealer. The tactic evades detection by having users manually run the malicious code. Two traffers groups, Slavic Nation Empire and Scamquerteo, are attributed to this campaign, suggesting shared materials and infrastructure.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | us002webzoom.us | — | 2024-10-18 | |
| domain | us01web-zoom.us | — | 2024-10-18 | |
| domain | web05-zoom.us | — | 2024-10-18 | |
| hostname | meet.google.us07host.com | — | 2024-10-18 | |
| hostname | meet.google.webjoining.com | — | 2024-10-18 |