RSS Amplifier

Ward Security Blog · Apr 4, 2026

North Korea is weaponizing a "Microsoft Teams" meeting scam, but you can protect yourself

0
Sign in to vote or save

Cedric Fitzgerald · Ward Security Blog

Have you ever had a moment tearing your hair out trying to join a video call? You’re not alone.

I’m convinced everyone finds Microsoft Teams and similar programs a little annoying and unpredictable. Often you waste valuable minutes of your meeting trying to get it set up, with the right audio inputs, program updates, and restarts.

Maybe it’s not just Teams - but Zoom, Google Meet, or forbid WebEx or Chime. Sound familiar?

These small, inconvenient idiosyncrasies found in how video conferencing software has developed are being exploited on a scale never seen before, to great success. And it’s showing no sign of stopping.

So who’s behind this?

The actors of these campaigns are, unsurprisingly, financially motivated and have found success so far with several past campaigns. They primarily target the financial industry with the goal of stealing funds, shifting from traditional banking to cryptocurrency.

  • They go by several pseudonyms - APT38, UNC1069, the Lazarus Group, etc.

Geopolitical reasons such as sanctions and a closed, dictatorial government have largely cut off North Korea from participating in the global economy. Out of necessity, this has led to unexpected skill development in cybercrime in the country to fund the country’s hard currency reserves.

Over the past couple of years, one type of IT worker fraud (“laptop farms”) has exploded, in which DPRK actors interviewed and subsequently were employed with US-based tech companies. Laptops sit in “farms” in buildings throughout the US, remotely controlled by workers in Asia. Amazon and other large US companies have already been infiltrated.


They’ve found success with these types of fraud, and it’s only natural that the techniques have evolved to become more nuanced and cunning.

Image
A malicious webpage masquerading as Teams, downloading a malicious file.

Actors are using the same storied social engineering techniques (download this malicious file!) but exploiting it where we are the least on guard and have a heightened sense of urgency. It’s the recipe for a perfect storm, and common in the past guidance we’ve issued.

This type of scam, involving a strong premise and build-up to establish credibility, is not new.

On an episode of “Darknet Diaries”, a podcast, a “physical penetration” tester team has been tasked by a company with the goal of entering a highly secured facility Zed HQ - complete with barbed wire, a gated security system, and patrolling security guards.

How did they get in eventually? All it took was using some names from LinkedIn profiles of company VPs, a convincing back & forth email chain, and a forwarded message to one of the unsuspecting employees of this facility. They leveraged this to not only get in once, but stay the whole day and obtain a visiting guest pass for unobstructed entry to the facility.

Instead of the DPRK threat actors sending a sketchy link (the equivalent of showing up to the door unannounced at Zed HQ), they create an entire fake company (equivalent to the aforementioned email chain). The Github comment belows is from the developer who got pwn’d describing the attack:

A maintainer of popular open source software “axios” describing how he got pwned

In short, what the maintainer experienced was a cultivated premise & buildup:

  1. Create a fake company

  2. Create a fake Slack workspace

  3. Create fake content in the Slack workspace and members

  4. Invite the target to the Slack workspace

  5. Schedule a meeting with the target

  6. Embed a “RAT” (Trojan program) into the “meeting” site

  7. User downloads the “RAT” and attacker now has full access to target’s PC

  8. Attacker can access all files and credentials on the machine for financial gain

Image
A similar type of attack in Teams

This type of cunning attack can happen to anyone - even a highly technical package maintainer. As humans, we’re not meant to be in “on-guard” mode all the time. It’s stressful, impossible, and impractical. Looking back in retrospect, you can say this would have been easy for you to catch.

But when you’re late for a meeting because your kid decided to come into your office, you encounter a common software problem, and you’re not looking at the address bar. It’s the recipe for a perfect storm.

Notice how in all of the examples the user is in Chrome? Chrome does not protect you against net new phishing sites. Stuff gets through all the time - more than not. Modern antivirus won’t always help with a net new binary made just to target YOU.

It’s partially the software UX fault for bringing us here. Poorly designed software creates the urgency and confusion attackers exploit.

And the threat actors’, obviously. But we can’t easily fix these. There are things we can, though.

  • Use well trusted channels for communication.

  • Vet individuals you’ve never met online. Look into their backgrounds and company/employment. Get a mutual reference.

    • If something seems off, it probably is.

  • Scrutinize online meeting links heavily - it’s the new attack vector. Note the subtleties - below they use a Calendly (legit) link at first then reschedule the meeting, sending the fake link afterwards.

  • Tools for detecting spear phishing attacks like this exist.

    • Shameless plug: Consider using the Ward browser extension, which flags “typosquatted” URLs and malicious instructions embedded in sites.

Image
A cunning Telegram message attack
  • https://github.com/axios/axios/issues/10636#issuecomment-4182134203

  • https://www.wiz.io/academy/threat-intel/what-is-apt38

  • https://cybersecuritynews.com/amazon-catches-north-korean-it-worker/

  • Taylor Monahan (X/Twitter) - A prominent figure in the crypto space who shared context on this technique

Thanks for reading! It’s been a while since my last article but I want to keep it coming. As always, if you’ve got suggestions send them in! Hit me up: cedric@tryward.app

-Cedric

No posts

Read the original on wardblog.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.