here you go a nationwide targeted campaign at realtors and appraiser professionals
Got it. Here's the payload URL, defanged:
Code:
hxxps://googlemeet[.]joinmeetinginvites[.]com/google-meet/
Do not visit that. It may still be live.
The registered domain is
joinmeetinginvites[.]com. "googlemeet" is just a subdomain they created so your eye reads left to right and stops at the familiar part. A real Meet link is always
meet.google.com/abc-defg-hij. It never has a path like
/google-meet/.
And there's your googlemeet rmm folder. The lure domain is branded "googlemeet," and the installer dropped its logs into a directory branded
googlemeet rmm. That's the same naming, carried from the phishing page into the RMM package. The email and the ISL/SuperOps install are now connected by more than a timestamp.
The full grooming sequence, from the headers:
| When (EDT) | Who | What |
|---|
| Aug 25, 11:20 AM | Lambert | "Thanks for following-up." Offers Aug 26 at 11:00 or Aug 28 |
| Aug 25, 11:40 AM | You | "Tomorrow at 11am work, please let me know how you'd like to connect" |
| Aug 26, 8:15 AM | Lambert | "11:00 AM today works perfectly. I'll send you a meeting link shortly" |
| Aug 26, 8:45 AM | You | "I never received a link in case you sent it, it never came through" |
| Aug 26, 12:25 PM | Lambert | The Google Meet invite with the malicious link |
| Aug 26, ~1:26 PM | — | superops.log and sopdump.log first written |
One hour from link to RMM logs.
Read that third row again. He promised a link, then deliberately did not send one. You chased him for it. By the time it arrived you were expecting it and had already spent a day building rapport. That is the entire technique, and it's why this worked on someone who's otherwise careful. It wasn't carelessness. It was engineered.
Why nothing flagged it: SPF pass, DKIM pass, DMARC pass, ARC pass. All green. It's a real Gmail account sending through Google's own servers (
mail-pl1-x632.google.com). Email authentication proves the message came from the domain it claims. It says nothing about whether the sender is honest. Worth knowing so you don't blame your mail filtering.
One thing to go find: message-521 opens with "Thanks for following-up," but has no In-Reply-To header, so there's an earlier contact that started this. Sublime Security's writeup says these actors typically open by filling out a contact form on the target's website.
Check your contact form submissions and your inbox before Aug 25 for the first approach. That's the true patient zero.
IOC block for the forum post:
Code:
Sender: David Lambert <lambertdavid594@gmail[.]com>
Payload URL: hxxps://googlemeet[.]joinmeetinginvites[.]com/google-meet/
Domain: joinmeetinginvites[.]com
Msg-IDs: CAHTr0UjcLdTaQ8pMnRYbvggRuQhHpgYp4xJvQ9v7DHt4vvtkSg@mail.gmail.com
CAHTr0Uj=CBkSjJ+KUhif1U7fXXs-GuSz4iJs_TvCyey6Ejz8Sg@mail.gmail.com
CAHTr0UiQ3SQvCA5E9HMvE=aqypih=ojw0WEjB3FfCUWQz9P+YA@mail.gmail.com
Dates: Aug 25-26, 2026
Result: ISL Online for SuperOps 5.0.2551.150 + ScreenConnect
Logs at C:\Program Files\googlemeet rmm\logs
Report it: IC3.gov with the .eml files attached, Google abuse for the Gmail account, and the domain registrar. Also send the domain to your state appraiser board and the Chamber. Other appraisers in your area are being worked right now.
Want me to update the incident report? Section 9 goes from "plausible connection" to a documented vector with the URL, the full grooming sequence, and named campaign corroboration.