Lure theme
Fake meeting or conferencing app
A page imitating Zoom, Google Meet or Microsoft Teams that reports the call cannot start, usually blaming the microphone or camera. The remedy on offer is a pasted command. This theme is normally reached through an invitation rather than through browsing, which makes it the most targeted of the set — and it is the one most often aimed at macOS.
- First reported
- 2024-08
- Targets
- Windows · macOS
- Campaigns on record
- 3
Approximate. Meeting-themed pages are reported from around August 2024 and expand through 2025, including in targeted campaigns against people working in cryptocurrency.
Also reported as Fake Zoom page · Fake Google Meet · Fake Teams meeting · Microphone driver error lure · Meeting join error
What a victim sees
A convincing join screen or in-call error: platform colours, the usual row of controls, perhaps a participant tile, and a modal saying a device could not be initialised or a driver or codec is missing. The pressure here is supplied by the victim, not the page — someone who believes they are late for a meeting will try the first fix they are given. The instructions are presented as ordinary troubleshooting and are tailored to whichever operating system the page detects.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
Conferencing platforms diagnose devices inside their own application, and their fixes are buttons. Check the address bar as well: a real Meet, Zoom or Teams link lives on the platform's own domain.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
Phantom Meet fake download sites
Status as last assessed: ActiveSekoia grouped a large set of counterfeit download sites with the fake Google Meet pages it was tracking, on registration records, passive DNS, and page construction that repeats across the estate. The brands are borrowed or invented outright: video conferencing, document utilities, several games that do not exist, Web3 browsers and messengers, a metaverse client. Every page runs the same script — the visitor is told a check has failed, then walked through pasting a command. Windows visitors were sent Stealc or Rhadamanthys; macOS visitors were sent AMOS. Distribution ran through affiliate crews rather than one operator, which is why the naming conventions wander while the page templates do not. We hold this as a single estate because that is how the source groups it; the individual lure themes are tagged separately below.
ID 8562b3edFirst seen —Last seen —Windows · macOSGoogle Meet clones, three stealers
Status as last assessed: ActiveSekoia's research team followed a set of look-alike hosts that reproduce the joining screen of Google's video-conference service, down to an invented meeting code in the path. A dialog claims the microphone or headset has failed, and the repair button loads the clipboard. On Windows the pasted line calls mshta against a remote HTML Application; its obfuscated VBScript kills the parent process, pulls two executables over BITS, then reports success or failure together with the machine's public address. What lands is Stealc and Rhadamanthys, each wrapped by the HijackLoader crypter. Visitors identified as macOS receive a disk image instead, recognised as AMOS. Two Russian-speaking traffer crews, Slavic Nation Empire and Scamquerteo, sent victims to the same template, and a Telegram bot fed by the operators' backend counted every visit and download.
ID 19b23e06First seen —Last seen —Windows · macOSOBSCURE#BAT via a Discord lure
Status as last assessed: ActiveOBSCURE#BAT is the name Securonix gave to activity that installs an altered build of r77, an open-source rootkit whose value to an operator is staying hidden and staying put. Microsoft attributes one of the lure pages it pulls apart in this write-up to that same cluster. The page presents itself as a Discord server that wants a visitor identified before letting them join, and borrows the platform's own logo to sell the idea. Its script waits for the verify button and then uses the browser's clipboard interface to load a command, with no hidden frame and no message from another document involved — plainer than the other example Microsoft dissects, where a concealed frame signals the parent page. Recorded alongside it are a landing page, a batch file on a public file host, and two addresses used for control between February and March 2025.
ID 092c751dFirst seen 2025-02-24Last seen 2025-03-27Windows