Security researchers have warned of a new wave of sophisticated social engineering attacks linked to North Korea, exploiting fake Microsoft Teams domains to deliver malicious software.
The campaign, tied to a threat group known as UNC1069, appears highly targeted and professional, focusing on individuals and organizations rather than random users.
Researchers from the Security Alliance identified a newly registered malicious domain, onlivemeet[.]com, designed to impersonate Microsoft Teams meeting links. They highlighted that even seasoned professionals could be vulnerable due to the realistic appearance and strategic delivery of the attacks.
The scope and sophistication of these efforts underscore the growing threat posed by state-backed cyber operations targeting professional environments.
Inside the UNC1069 Campaign
UNC1069 is a financially motivated threat group with a history of targeting professionals through nuanced social engineering strategies. Unlike generic phishing campaigns, the group carefully designs interactions to appear legitimate and contextually relevant, leveraging trust built from previous communications or professional settings.
It’s not just convincing false links that are being used. In the current malware campaign, researchers observed several key delivery methods. For example, attackers revive old conversations from compromised Telegram and LinkedIn accounts to make outreach appear familiar to recipients. They also pose as partners, investors, or recruiters, sending messages through fake or impersonated Slack channels.
This hijacking of old accounts may help these links bypass built-in security features of Microsoft Teams, such as link scanning, since they come from previously approved accounts.
Additionally, attackers schedule meetings via legitimate tools like Calendly to enhance credibility and reduce suspicion. These techniques allow them to integrate seamlessly into professional workflows, increasing the likelihood that targets will engage with the malicious content.
Once a user clicks a provided meeting link, they are redirected to a fake Microsoft Teams interface. These counterfeit pages are highly convincing, replicating the platform’s design and functionality. A typical message on the page claims that the “TeamsFx SDK” has been deprecated and requires an immediate update.
When victims download what they believe is a necessary fix, they inadvertently install a Remote Access Trojan (RAT), granting attackers persistent access to sensitive systems and data.
The campaign’s targeting is sector-specific, with professionals in technology, finance, and consulting identified as primary victims.




