Not only DPRK. A vibe-coded phishing frontend for Microsoft Teams, found in the wild. With the proliferation of capable, unrestricted LLMs, we often observe unaffiliated threat actors deploying fully vibe-coded malware infrastructure. In this example, an endpoint misconfiguration exposed the phishing kit's assets along with the LLM's comments. Interestingly, the threat actor most likely framed the task as a benign development job - a custom video conferencing platform called "Lassy Meet" - traces of which can also be found on the suspicious GitHub organization that also appears to be LLM-automated. However, the comments reveal the intent. IOCs: 223.165.6[.]141 netwitz.zoom01[.]us teams.mlcrosoff[.]com github[.]com/altosecteam-org

Sep 24, 2026 · 1:54 PM UTC

1
5
21
3,414
Sort replies: Relevant Recent Liked
Replying to @_SEAL_Org
even their cover story kept a diary
42