A threat actor impersonating a representative from a major crypto news site targeted cybersecurity researchers around Black Hat and Def Con with malware disguised as a fake conference planning document. The hacker reached out via public replies and direct messages on X, sharing a legitimate Google Doc that appeared to contain encrypted materials.
The document included a sidebar that mimicked an encryption interface, tricking targets into entering a fake decryption key. This was the first step in a multi-stage attack designed to install malware on macOS and Windows systems. Huntress researchers identified attempts to deliver an Apple infostealer, a repurposed remote desktop tool for Windows, and a counterfeit Ledger wallet installer.
The campaign relied on Google App Script to customize the Google Docs interface, lending it a veneer of legitimacy. Google has not yet responded to inquiries about the incident. Similar tactics have been used by state-backed hackers, but this case stands out for its use of a real Google Doc and feature.
Security teams should remain cautious of unsolicited conference invitations and verify unexpected documents before opening them.



