#MiroTalk

Incident/Operation

2024-07-15 • This Meeting Should Have Been an Email

MiroTalk is a fraudulent macOS video-conferencing application distributed in July 2024 from a cloned site impersonating a legitimate browser-based calling service. The disk image installed North Korea-linked malware capable of stealing browser data, keylogging, and deploying remote-administration software, and analysis connected it to an older JavaScript variant. Related Lazarus activity used similarly cloned meeting platforms and BeaverTail delivery on both Windows and macOS, making MiroTalk a malicious application and social-engineering vehicle rather than a distinct threat operation.

Tagged Reports

« Back