Another day another North Korean scammer

2025-03-12 dazhengzhang

https://archive.is/WxtB0

Thumbnail for Another day another North Korean scammer

The thread describes a North Korea-linked social-engineering attempt that used a fake executive persona and legitimate-looking scheduling material to build trust with the target. The attacker moved the interaction from a Google Meet scheduling flow to a fake Zoom-style site at businessmeet.xyz after claiming an internal meeting issue. The fake meeting page behaved like a conferencing app, then the caller claimed not to hear the victim and asked for a screenshot through in-call chat; the author suspected the site may have tried to determine the operating system before prompting further action. The excerpt also notes a lookalike email/web domain, openfort.video, used to impersonate Openfort rather than the legitimate openfort.io domain.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN businessmeet.xyz 2025-03-12 2025-06-20
URL http://openfort.io 2025-03-12 2025-03-12
URL http://openfort.video 2025-03-12 2025-03-12
URL http://businessmeet.xyz 2025-03-12 2025-03-12
DOMAIN openfort.io 2025-03-12 2025-03-12
DOMAIN openfort.video 2025-03-12 2025-03-12

Related Actors

Related Reports

« Back