A recent Malwarebytes report says a fake Google Meet update page is abusing a legitimate Windows device-enrollment mechanism. That makes the attack unsettling for a simple reason: no password theft is required at the start, and there may be no obvious malware prompt at all.
According to the report, the fake update page impersonates Google Meet well enough to pass a casual glance, then uses the ms-device-enrollment URI scheme to open a native Windows enrollment flow. If the victim keeps going, the machine can reportedly be enrolled into attacker-controlled management.
Instead of stealing credentials first, the attacker aims for control of the device itself.
This is phishing that leans on real operating-system workflows. The browser is just the handoff point.
Most people think phishing means a fake login page, a password prompt, or a malicious download. This reported campaign is different because it uses a legitimate Windows feature meant for IT provisioning.
Instead of seeing a suspicious executable, the victim sees a real system dialog. Native system prompts naturally feel safer than random browser pop-ups.
The click does not just open another webpage. It reportedly hands the browser session off to a trusted Windows workflow, which means many people will assume they are still moving through a legitimate update process.
The attacker is exploiting trust in the operating system itself, not only trust in a brand or domain.
That is a very different risk profile from a simple credential phish.
Open Windows Settings and review Accounts > Access work or school. Disconnect any unknown or suspicious enrollment immediately. Treat the device as potentially compromised and involve IT or incident response rather than assuming a password reset will fix the problem.
The browser remains the trust handoff point. If the fake update page does not get the click, the chain stops before Windows ever gets involved.
Google Meet runs in the browser - there is no separate desktop client that needs an update before you can join a call. That one fact defuses the entire lure: a page telling you Meet needs an update is asking you to do something the real product never does. The same logic covers most web apps. Browser-based tools update silently through the browser, and the browser itself updates through its own menu - never through a webpage you happened to land on.
When any update prompt interrupts you mid-task, close it and go to the source instead: open the application, or the browser's own About page, and check for updates there. A real update will still be waiting in five minutes. A lure depends on you acting before you check.
Links do not only open webpages. Schemes like mailto:, tel:, and vendor-specific handlers tell the browser to pass the request to another program on the machine. That handoff is what makes this class of attack attractive: the moment a native dialog opens, the suspicious address bar is out of sight and the operating system's trusted styling takes over. The dialog is genuine - it is simply being fed attacker-controlled input.
So treat the transition itself as the checkpoint. When a click on a webpage produces a system dialog you did not expect - enrollment, remote access, certificate installation, anything mentioning management - the safe response is to cancel, not to study the dialog for reassurance. It will always look legitimate, because it is a real dialog.
Because the handoff starts in the browser, the browser is also the cheapest place to break the chain. PhishClean analyzes the page you are actually on, locally - lookalike branding, suspicious hosting, fake update framing - before a convincing button can pass you into a system workflow. It is one layer against this whole class of phishing attacks, not just one campaign. And if you already clicked through something similar, work through what to do if you clicked a phishing link in addition to reviewing your enrollment settings.
This post is based on Malwarebytes' March 6 article One click on this fake Google Meet update can give attackers control of your PC.
Why is the fake Google Meet update page dangerous?
Because it reportedly uses a legitimate Windows device-enrollment mechanism to open a real system workflow that can enroll the victim's PC into attacker-controlled management.
Why is this different from normal phishing?
The attack does not need to steal a password first or drop obvious malware. It abuses a legitimate operating-system feature and trusted management infrastructure instead.
What should someone do if they clicked and completed enrollment?
Treat the machine as potentially compromised, check Access work or school settings, disconnect any unknown enrollment, and involve IT or incident response immediately.
PhishClean helps detect suspicious pages and browser-level phishing signals before a single click moves into a much riskier workflow.
Install PhishClean FreeIf this helped, share it with someone who would benefit from it, or subscribe for new browser-security guides from PhishClean.
Get practical phishing and browser-safety articles in your inbox. No salesy drip, just new guides and product updates when they are worth sending.