Cybersecurity Researchers Targeted with Malware via Fake Crypto Conference Lure on Google Docs
A threat actor posing as an employee of a prominent cryptocurrency news platform targeted multiple cybersecurity professionals around the time of the Black Hat and Def Con security conferences. The operation used social media interactions and customized Google Docs documents to attempt the deployment of malware across different operating systems, according to research published by security firm Huntress.
What Happened
The campaign began on social media platform X, where the attacker contacted conference attendees through both direct messages and public replies. Communicating in broken English, the individual inquired whether the targets planned to attend upcoming events and referenced a conference purportedly run by a well-known crypto news outlet.
To advance the scheme, the attacker shared a legitimate Google Doc framed as a planning document for the fictitious conference. The document made use of Google Apps Script, a development platform allowing users to customize interfaces inside Google Docs with menus and panels. In this instance, the hacker built a custom sidebar that falsely claimed the document was encrypted, instructing the recipient to input a supplied decryption key.
A Huntress researcher engaged with the attacker and feigned compliance to observe the workflow. The verification mechanism was designed to initiate a multi-stage infection routine tailored to the victim’s operating system. The malware payload varied depending on whether the target ran macOS or Windows. Huntress found that the attacker attempted to deliver an information-stealing program for Apple systems, a remote desktop management utility repurposed as malware for Windows, and a counterfeit installer disguised as the Ledger cryptocurrency hardware wallet software.
Key Highlights
- Attackers targeted attendees around the Def Con and Black Hat cybersecurity conferences via public replies and direct messages on X.
- The lure involved an alleged cryptocurrency conference organized by a major industry news organization.
- The attack abused Google Apps Script within a legitimate Google Doc to present a fake decryption sidebar.
- Victims were directed to submit a decryption key to initiate malware delivery.
- Payloads identified by researchers included a macOS infostealer, a modified Windows remote desktop tool, and a counterfeit Ledger cryptocurrency wallet installer.
Why This Matters
Cybersecurity practitioners are historically frequent targets for malicious operations, including past campaigns involving advanced spyware and state-backed groups using social media personas. This incident highlights the exploitation of legitimate collaborative platforms like Google Docs and built-in developer features like Google Apps Script to create seemingly authentic interfaces, complicating visual detection before malware payloads are triggered.
What to Watch Next
TechCrunch reported reaching out to Google regarding whether the company had detected this specific activity or similar campaigns, and sending inquiries to the X account associated with the scheme. Formal updates or disclosures from Google or the platform administrators regarding security updates or account suspensions remain pending.
Frequently Asked Questions
Who was targeted in this campaign?
The attacker targeted cybersecurity professionals who were attending or engaging around the Black Hat and Def Con security conferences.
How was Google Docs used in the attack?
The attacker shared an authentic Google Doc containing a custom sidebar created via Google Apps Script. The sidebar simulated an encryption lock screen requiring a specific key to view the contents.
What types of malware were distributed?
According to Huntress, the attacker attempted to deliver an information stealer targeted at macOS, a remote desktop viewing tool configured as Windows malware, and a fake Ledger cryptocurrency wallet application.
Source: Huntress, with additional reporting from TechCrunch.
