Image: Sucuri
A deceptively crafted fake Google Meet page has surfaced on compromised WordPress sites, tricking unsuspecting visitors into manually executing PowerShell commands that unleash remote access malware. First uncovered by Puja Srivastava, Security Analyst at Sucuri, this threat demonstrates a troubling new trend in social engineering attacks: malicious command injection by human hands.
βThis phishing page is crafted to manipulate human behavior, not browser behavior,β Srivastava warns. βThe attacker isnβt stealing passwords through fake forms. Instead, they rely on the user to run a PowerShell script.β
The attack was initially discovered after a Sucuri customer noticed strange URLs and visitor complaints about odd prompts on their WordPress site. Upon deeper investigation, analysts found an HTML file posing as a legitimate Google Meet page, but with a sinister twist β instead of stealing credentials, it prompts users with a fake error modal claiming:
βMicrophone permission denied.β
To resolve this fake issue, users are told to copy and paste a PowerShell command into their system terminal β a clever manipulation disguised as a technical fix.
The HTML page is self-contained, with no external scripts, Google resources, or analytics β making it exceptionally stealthy.
βWhat makes this fake Google Meet file more dangerous than many weβve seen is its self-contained natureβ¦ The attacker knew what they were doing,β Srivastava notes.
The interface includes:
- A βJoin Nowβ button
- A fake error popup
- A βTry Fixβ button that copies a PowerShell command to the userβs clipboard
- Step-by-step instructions to launch PowerShell and run the code
When executed, the PowerShell command downloads an obfuscated payload (XR.txt) directly from the infected site. This script:
- Shows a βVerification Complete!β dialog as a decoy
- Uses XOR obfuscation to decode a hidden command
- Executes a remote access tool (noanti-vm.bat) into the AppData folder
The final payload β a Trojanized batch file β uses string slicing and environment variable tricks to dynamically construct and run malicious commands while evading detection.
βThe noanti-vm.bat file is a heavily obfuscated Windows batch scriptβ¦ detected as Trojan or RAT on VirusTotal.β
This attack leverages human behavior, not browser exploits. The attackerβs goal is simple: gain system access by convincing users to willingly execute malware under the pretense of troubleshooting.
Srivastava explains:
βThe attackers are betting on the users trust and their desire to quickly resolve a perceived technical issue.β
By mimicking a known interface and simulating a relatable problem (mic access), the attacker weaponizes trust and a userβs desire for quick fixes.
This fake Google Meet phishing tactic showcases how attackers are evolving β blending design precision, technical manipulation, and psychological insight to create incredibly effective traps.
As Srivastava puts it:
βBy understanding the mechanics of this attack and remaining vigilant, we can significantly reduce the risk of falling victim to this dangerous deception.β
Related Posts:
- Stealthy Malware Hides in WordPress Database, Steals Payment Data
- PHP Reinfector Malware Wreaks Havoc on WordPress Sites
- Blackout Mode: Microsoft Teams to Block Screenshots in Meetings
- Beware of Fake Google Meet Invites: ClickFix Campaign Spreading Infostealers
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.