Campaign record
Google Meet clones, three stealers
Fake Google Meet conference pages delivering Stealc, Rhadamanthys and AMOS
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- Unrecorded
- Indicators
- 34
- Sources
- 1
- Targets
- Windows, macOS
- Fake video conference page
- AMOS (Atomic macOS Stealer)
- HijackLoader
- Rhadamanthys
- Stealc
- Traffers affiliate distribution
Original research
- Sekoia.io2024-10-17Vendor researchFirst account
ClickFix tactic: The Phantom Meet
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Sekoia's research team followed a set of look-alike hosts that reproduce the joining screen of Google's video-conference service, down to an invented meeting code in the path. A dialog claims the microphone or headset has failed, and the repair button loads the clipboard. On Windows the pasted line calls mshta against a remote HTML Application; its obfuscated VBScript kills the parent process, pulls two executables over BITS, then reports success or failure together with the machine's public address. What lands is Stealc and Rhadamanthys, each wrapped by the HijackLoader crypter. Visitors identified as macOS receive a disk image instead, recognised as AMOS. Two Russian-speaking traffer crews, Slavic Nation Empire and Scamquerteo, sent victims to the same template, and a Telegram bot fed by the operators' backend counted every visit and download.
Overlap with other campaigns
We compared the 34 indicators in this record — covering 10 distinct registrable domains — against the 43 other published campaigns in this corpus.
Phantom Meet fake download sites
2026-08-071 of the 34 indicators in Google Meet clones, three stealers also appear in this campaign.
Shared registrable domains (2)
- domain, shown defanged for safety: us18web-zoom dot us
- domain, shown defanged for safety: webjoining dot com
AMOS via a shared delivery layer
2026-08-071 of the 34 indicators in Google Meet clones, three stealers also appear in this campaign.
Shared registrable domain (1)
- domain, shown defanged for safety: carolinejuskus dot com
A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.
What changed since publication
The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.
- Indicators checked
- 8 of 34
- Checks recorded
- 16
- Checks since publication
- 16
- Never checked
- 26
Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 26 indicators have never been checked by us at all.
Current recorded state
- 8 Unregistered
- 26 Not checked by us
Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Clipboard injection | 15 of 4434% | T1204.004 |
| mshta.exe | 7 of 4416% | T1218.005 |
| BITS transfer download | 2 of 445% | T1197 |
No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
34 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Google Meet clones, three stealers”, campaign ID 19b23e06, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/19b23e06/fake-google-meet-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.