{"id":8813,"date":"2025-11-29T10:03:48","date_gmt":"2025-11-29T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/29\/beware-of-weaponized-google-meet-page-uses-clickfix-technique-to-deliver-malicious-payload\/"},"modified":"2025-11-29T10:03:48","modified_gmt":"2025-11-29T10:03:48","slug":"beware-of-weaponized-google-meet-page-uses-clickfix-technique-to-deliver-malicious-payload","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/29\/beware-of-weaponized-google-meet-page-uses-clickfix-technique-to-deliver-malicious-payload\/","title":{"rendered":"Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload"},"content":{"rendered":"<p>    Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new, highly sophisticated malware campaign has been identified targeting remote workers and organizations through a fake Google Meet landing page.<\/p>\n<p>Hosted on the deceptive domain gogl-meet[.]com, this attack leverages the \u201c<a href=\"https:\/\/cybersecuritynews.com\/clickfix-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix<\/a>\u201d social engineering technique to bypass traditional browser security controls and deliver a Remote Access Trojan (RAT) directly to the victim\u2019s system.<\/p>\n<p>The attack begins when a user navigates to the fraudulent site, which is visually indistinguishable from the legitimate Google Meet interface. Instead of a video feed, the user is interrupted by a pop-up error message, typically claiming a camera or microphone issue titled \u201cCan\u2019t join the meeting.\u201d<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgtUHE-9Pr2t8qld8jygJYJX1mr0MBAy4mNgZSvcw3KdQrGeEdRVYbOkfxFq7TW7bOVo-mppbUqcPUVz9Sz5pomkz2bo-1-iHEkcdZS-9WiYGl4y9H00dHpQBi3wOwvDx8OTR98xELRUap4Yd1RRpgv1N51zG9vLVPz82YG5-xyEzZ2ydiVBoufrnmACrrU\/s16000\/Google%2520Meet%2520clickfix%2520page.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Unlike standard phishing that asks for credentials, this page offers a technical \u201cfix\u201d that requires physical user interaction. The prompt instructs the victim to perform a specific sequence of keystrokes: Press the Windows key + R, then CTRL + V, and finally Enter.<\/p>\n<p>Unbeknownst to the user, clicking the \u201cJoin now\u201d or \u201cFix\u201d button on the page triggers a JavaScript function that copies a malicious PowerShell script to their clipboard.<\/p>\n<p>By following the manual keystroke instructions, the user unwittingly pastes and executes this script via the Windows Run dialog, effectively bypassing browser-based security filters such as <a href=\"https:\/\/cybersecuritynews.com\/google-chromes-enhanced-safe-browsing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Safe Browsing<\/a> and SmartScreen.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-forensic-analysis-and-indicators\"><strong>Forensic Analysis and Indicators<\/strong><\/h2>\n<p>Recent incident response activities involving gogl-meet[.]com have confirmed that this chain leads to a RAT infection. Forensic analysis of affected systems identified the infection\u2019s root cause through the Master File Table (MFT).<\/p>\n<p>Specifically, the MFT entry for the dropped payload revealed critical origin data in its Alternative Data Stream (ADS), capturing both the ClickFix downloaded file and the referrer URL gogl-meet[.]com.<\/p>\n<p>This forensic artifact is crucial for defenders, as it definitively links the execution of the RAT back to the browser-based <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> event rather than a typical drive-by download or email attachment.<\/p>\n<p>A distinct characteristic of this wave is the obfuscation used within the PowerShell payload itself. Threat actors have begun padding the malicious script with extensive comments containing trusted visual symbols, such as repeated green check marks (<img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/2705.png?ssl=1\" alt=\"\u2705\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">).<\/p>\n<p>When a user pastes the content into the small Windows Run box, these symbols may be the only visible text, visually reassuring the victim that the command is \u201cverified\u201d or safe [memory].<\/p>\n<p>This tactic also serves a technical purpose: it can push the actual malicious code (often an IEX download cradle) out of the immediate visible area of the dialog box, masking the script\u2019s true intent.<\/p>\n<p>While ClickFix (also associated with clusters like ClearFake) gained significant traction throughout 2024, this latest iteration demonstrates a shift toward hyper-targeted branding.<\/p>\n<p>Early campaigns impersonated generic browser updates or Word errors. Still, the shift to Google Meet simulation suggests a pivot toward targeting corporate environments where video conferencing glitches are a common, trusted friction point.\u200b<\/p>\n<p>Security teams are advised to update detection rules to flag PowerShell execution strings originating from the Run dialog that contain unusual Unicode characters or extensive comment blocks, which are tell-tale signs of manual execution.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/weaponized-google-meet-clickfix\/\">Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/weaponized-google-meet-clickfix\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Beware of Weaponized Google Meet Page uses ClickFix Technique to Deliver Malicious Payload A new, highly sophisticated malware campaign has been identified targeting remote workers and organizations through a fake Google Meet landing page. Hosted on the deceptive domain gogl-meet[.]com, this attack leverages the \u201cClickFix\u201d social engineering technique to bypass traditional browser security controls and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-8813","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8813"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8813"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8813\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}