• Welcome to AppraisersForum.com, the premier online  community for the discussion of real estate appraisal. Register a free account to be able to post and unlock additional forums and features.

Sign in with Microsoft?

1788550441584.png

yep, i just spent 2+ days trying to fight a hack with admin privileges wreak havoc on my PC. they tried to charge a ton but that was all blocked, a crazy amount of back and forth w gpt and claude trying to root all of this stuff out but finally just decided a wipe and fresh win 11 install was needed. luckily, my C is just a boot drive so getting Total back up in running was no problem all my data lives on another drive. Supposedly, a Google meet exploit but the only GM I've used was a client who video rang my phone for a split second. Who knows, people suck anyhoo I get this same popup now too
 
you too bro? :ROFLMAO:
 
I got a weird Google Meet phone call the other day. The phone rang with this odd ring, but because I never answer the phone anymore, I don't know what it was about. But it was creepy.
 
Yeah I mean it's not like I'm using edge or windows either. Firefox on Linux.

I got a weird Google Meet phone call the other day. The phone rang with this odd ring, but because I never answer the phone anymore, I don't know what it was about. But it was creepy.

Got an appraisal request email that looked like a legit estate request, but the lady was asking for a google meet or teams call to discuss. She also questioned if I covered the area, but didn't provide an address. Seemed sus so ignored it
 
I got a weird Google Meet phone call the other day. The phone rang with this odd ring, but because I never answer the phone anymore, I don't know what it was about. But it was creepy.



Yeah I mean it's not like I'm using edge or windows either. Firefox on Linux.



Got an appraisal request email that looked like a legit estate request, but the lady was asking for a google meet or teams call to discuss. She also questioned if I covered the area, but didn't provide an address. Seemed sus so ignored it

YOU GOTTA BE FKN KIDDING ME THAT WAS THE EXACT EMAIL I GOT
 
Last edited:
here you go a nationwide targeted campaign at realtors and appraiser professionals

Got it. Here's the payload URL, defanged:
Code:
hxxps://googlemeet[.]joinmeetinginvites[.]com/google-meet/
Do not visit that. It may still be live.
The registered domain is joinmeetinginvites[.]com. "googlemeet" is just a subdomain they created so your eye reads left to right and stops at the familiar part. A real Meet link is always meet.google.com/abc-defg-hij. It never has a path like /google-meet/.
And there's your googlemeet rmm folder. The lure domain is branded "googlemeet," and the installer dropped its logs into a directory branded googlemeet rmm. That's the same naming, carried from the phishing page into the RMM package. The email and the ISL/SuperOps install are now connected by more than a timestamp.
The full grooming sequence, from the headers:
When (EDT)WhoWhat
Aug 25, 11:20 AMLambert"Thanks for following-up." Offers Aug 26 at 11:00 or Aug 28
Aug 25, 11:40 AMYou"Tomorrow at 11am work, please let me know how you'd like to connect"
Aug 26, 8:15 AMLambert"11:00 AM today works perfectly. I'll send you a meeting link shortly"
Aug 26, 8:45 AMYou"I never received a link in case you sent it, it never came through"
Aug 26, 12:25 PMLambertThe Google Meet invite with the malicious link
Aug 26, ~1:26 PM—superops.log and sopdump.log first written
One hour from link to RMM logs.
Read that third row again. He promised a link, then deliberately did not send one. You chased him for it. By the time it arrived you were expecting it and had already spent a day building rapport. That is the entire technique, and it's why this worked on someone who's otherwise careful. It wasn't carelessness. It was engineered.
Why nothing flagged it: SPF pass, DKIM pass, DMARC pass, ARC pass. All green. It's a real Gmail account sending through Google's own servers (mail-pl1-x632.google.com). Email authentication proves the message came from the domain it claims. It says nothing about whether the sender is honest. Worth knowing so you don't blame your mail filtering.
One thing to go find: message-521 opens with "Thanks for following-up," but has no In-Reply-To header, so there's an earlier contact that started this. Sublime Security's writeup says these actors typically open by filling out a contact form on the target's website. Check your contact form submissions and your inbox before Aug 25 for the first approach. That's the true patient zero.
IOC block for the forum post:
Code:
Sender:      David Lambert <lambertdavid594@gmail[.]com>
Payload URL: hxxps://googlemeet[.]joinmeetinginvites[.]com/google-meet/
Domain:      joinmeetinginvites[.]com
Msg-IDs:     CAHTr0UjcLdTaQ8pMnRYbvggRuQhHpgYp4xJvQ9v7DHt4vvtkSg@mail.gmail.com
             CAHTr0Uj=CBkSjJ+KUhif1U7fXXs-GuSz4iJs_TvCyey6Ejz8Sg@mail.gmail.com
             CAHTr0UiQ3SQvCA5E9HMvE=aqypih=ojw0WEjB3FfCUWQz9P+YA@mail.gmail.com
Dates:       Aug 25-26, 2026
Result:      ISL Online for SuperOps 5.0.2551.150 + ScreenConnect
             Logs at C:\Program Files\googlemeet rmm\logs
Report it: IC3.gov with the .eml files attached, Google abuse for the Gmail account, and the domain registrar. Also send the domain to your state appraiser board and the Chamber. Other appraisers in your area are being worked right now.

Want me to update the incident report? Section 9 goes from "plausible connection" to a documented vector with the URL, the full grooming sequence, and named campaign corroboration.
 
Find a Real Estate Appraiser - Enter Zip Code

Copyright © 2000-, AppraisersForum.com, All Rights Reserved
AppraisersForum.com is proudly hosted by the folks at
AppraiserSites.com
Back
Top