North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
Silent Push found North Korean IT workers recruiting on-camera proxies for job interviews while remotely controlling the computer, defeating identity and location checks.
Silent Push researchers engaged the "Tec Guru" persona via Discord and Telegram and assessed with moderate-to-high confidence that the operator is a North Korean IT worker recruiting on-camera proxies in the US, Europe, and Latin America for a 35/65 revenue split. During Google Meet interviews, the proxy stays on camera while the real worker supplies answers via ChatGPT-generated prompts, real-time messaging, or remote-control tools such as AnyDesk and TeamViewer. Successfully placed workers can access source code, cloud tenants, and CI/CD systems, and payments create sanctions exposure; the US, Japan, South Korea, and eight other governments issued a joint identity-verification alert on July 31, 2026.
Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
Microsoft warns of a human-operated campaign where attackers pose as IT support in Teams to gain remote PC control and reach domain controllers.
Microsoft Threat Intelligence observed attackers abusing Microsoft Teams external collaboration to impersonate IT/helpdesk staff, persuading employees to grant screen control via Quick Assist or RMM tools. Operators deploy malicious MSI packages via silent msiexec, run encrypted JavaScript implants through portable Node.js, and persist via EdgeUpdate Run keys or Startup folder entries. The Node.js backdoor uses HTTPS long-polling C2, captures screenshots, enumerates Active Directory, and moves laterally over WinRM (TCP 5985) to domain controllers and certificate authorities. Initial access maps to MITRE ATT&CK T1566.003 (Spearphishing via Service); no Teams vulnerability is exploited.
Risky Bulletin: BEC campaign steals €35 million from French notaries
Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.
A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
Unit 42 details 'Spring Ring', a vishing campaign using fake IT support on Microsoft Teams to reach 150+ employees at 10+ companies.
Palo Alto Networks Unit 42 documented 'Spring Ring', a voice-phishing campaign that ran January to April 2026, using 26 attacker identities and fake Microsoft 365 tenants such as 'ITProtectionDepartment' to impersonate internal IT support on Microsoft Teams. One path used Quick Assist or downloaded remote-support tools to run an obfuscated PowerShell script that disabled malware scanning before contacting C2; the other delivered a cloud-hosted file triggering browser hijacking, SMB internal network scanning, and a PetitPotam NTLM relay attempt against domain controllers to gain domain-level privileges. Both intrusion attempts were blocked before attackers reached their objectives. Collaboration-platform phishing alerts rose to 42% of Unit 42's telemetry in early 2026, up from 30%.
The sexy AI-powered dating app scams are here
Anthropic exposed a network of roughly 28 AI-driven dating apps using autonomous personas and gig workers to defraud paying users.
Anthropic threat intelligence uncovered a fraud network of around 28 dating apps after a prepaid account sent over 100,000 Claude API requests daily, with most chats run by autonomous AI personas and no human agent. Researchers Matthew Gore-Kormanik and Anthropic's Chris Cronbaugh documented apps including Dora, Romi, and Doni, which monetize conversations via coins; gig workers were hired only to pass liveness checks and select pregenerated replies. An operations manual written in Chinese was found inside the Doni app, and Anthropic published findings in its September 2026 AI misuse report.
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Abnormal Security details iAuthFlow v2, a $10,000 phishing kit that enrolls attacker-controlled passkeys on Google accounts, persisting through password resets.
Abnormal Security analyzed iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for a $10,000 base price with additional capability modules sold separately. Using a browser-in-the-middle relay behind a trycloudflare.com subdomain with valid TLS, it captures Google logins and uses the authenticated session to enroll an attacker-controlled passkey within six seconds of login. Because the passkey persists after password changes and session revocation, operators regain mailbox access even after victims reset credentials. The build examined targets Google, while the seller advertises versions for Microsoft, iCloud, and LinkedIn.