17 votes

Does anyone recognize this phishing attack?

My friend owns a circus performance company, and she got a very real-seeming request to discuss a possible wedding gig. "Client" requested that she join a meeting link at h​tt​p​s:/​/​joininivite​.​es/egooglemeet​.​us to discuss (several zero-width spaces are pasted throughout that to make it unclickable). Friend joined the call and it asked her to update software in order to join, she didn't follow any links from the site directly but tried updating Chrome through Microsoft Store etc. This sounded fishy to me so I asked to see the URL and this definitely seems like a scam.

This seems extra concerning because:

  1. Initial outreach from scammer seemed genuine even when I read it specifically looking for signs of phishing
  2. Initial outreach from scammer was specifically tailored to friend's website content, this is exactly the kind of gig she would get booked for
  3. There were several back-and-forth legit-seeming emails before any meeting was agreed to

Friend now wants to make a post within her artist community to protect others and I'm wondering if anyone has already heard of this particular type of attack and has additional details that could help for informing non-tech-savvy performers about it (more specific than "have intuition about when URLs seem dodgy and never click install links that originated from email")

7 comments

  1. [3]
    nukeman
    (edited )
    Link
    Scammers have gotten a lot more persistent and tailored in the age of AI. They will keep you going for hours or days if it means they can get a decent payout (and even $100 is good for someone in...

    Scammers have gotten a lot more persistent and tailored in the age of AI. They will keep you going for hours or days if it means they can get a decent payout (and even $100 is good for someone in a developing country, never mind $1000 or $10000).

    Personally I’d look through old posts in r/scams, since they have a bigger archive than Tildes. But several things set this off for me:

    • egooglemeet.us: Weird link designed to vaguely resemble a legitimate Google invite.
    • Asking her to install/update software (typically this enables Remote Desktop for the scammer or a keylogger).
    • Asking her to meet outside of her channels: Stick to her approved channels (email, Zoom, telephone) to connect with clients for preliminary meetings.
    21 votes
    1. [2]
      ToteRose
      Link Parent
      This is probably the main recommendation I would emphasize. Even take it a step further and say that, if you are the person being contacted, you should be the one providing the meeting link...

      Asking her to meet outside of her channels: Stick to her approved channels (email, Zoom, telephone) to connect with clients for preliminary meetings.

      This is probably the main recommendation I would emphasize. Even take it a step further and say that, if you are the person being contacted, you should be the one providing the meeting link whenever possible. At the very least, you should choose the channel you are comfortable using and verify that any link shared by the other person is a legitimate, official link for that platform.

      18 votes
      1. freedomischaos
        Link Parent
        Also be prepared to double down "in case they have a technical problem with your link and they totally have one that works..." Basically don't click links you didn't source yourself. If you must...

        Also be prepared to double down "in case they have a technical problem with your link and they totally have one that works..."

        Basically don't click links you didn't source yourself. If you must click one, setup a VM preferably a Linux one (not that you can't pwn a Linux computer but it takes more effort and most auto attack stuff is exploited on windows)

        2 votes
  2. [4]
    Zorind
    Link
    I would redact that link or make it not clickable here. If that is the exact link, it’s definitely URL Phishing since it’s a typo of “joininvite”. I’ll try to grab a (trusted) resource on that...

    I would redact that link or make it not clickable here. If that is the exact link, it’s definitely URL Phishing since it’s a typo of “joininvite”.

    I’ll try to grab a (trusted) resource on that type of attack and reply to my own comment with it.

    7 votes
    1. [2]
      Zorind
      Link Parent
      This is is a link to some related information on a similar “fake update”,...

      This is is a link to some related information on a similar “fake update”, https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc, though likely more sophisticated than the one aimed at your friend.

      Your friend did everything right by trying to update “out of band”.

      Unfortunately, as nukeman mentioned, with LLMs it’s gotten a lot easier and cheaper to tailor phishing towards basically anyone with a public presence.

      17 votes
      1. RheingoldRiver
        Link Parent
        Thanks so much! Sent her this link

        Thanks so much! Sent her this link

        2 votes
    2. RheingoldRiver
      Link Parent
      Ah good point, I pasted in some zero-width spaces Thanks!

      I would redact that link or make it not clickable here.

      Ah good point, I pasted in some zero-width spaces

      I’ll try to grab a (trusted) resource on that type of attack and reply to my own comment with it.

      Thanks!

      5 votes