Tech

Fake crypto conference lures security researchers into Google Docs malware trap

A hacker impersonating a crypto news employee used a malicious Google Doc sidebar to deploy malware on macOS and Windows systems during the Black Hat and Def Con conferences.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
Someone targeted security researchers using a fake crypto conference as a lure
Cybersecurity

Security firm Huntress has detailed a targeted hacking campaign that exploited the social media platform X to reach cybersecurity professionals around the time of the Black Hat and Def Con conferences earlier this month. The attacker posed as an employee of a leading cryptocurrency news website, using public replies and direct messages to approach victims.

The campaign relied on a legitimate Google Doc that appeared to be a planning document for a fake crypto conference. To make the document appear interactive and secure, the hacker used Google App Script to create a sidebar that mimicked an encryption tool. This interface tricked targets into believing the document was encrypted and required a key to unlock.

According to Huntress, the goal was to have victims enter a fake decryption key provided by the hacker. This action initiated the installation of malware tailored to the victim’s operating system. The payloads included an infostealer for Apple computers, a remote desktop viewing tool repurposed as malware for Windows, and a fake installer for the Ledger cryptocurrency wallet.

The sophistication of the attack lay in its use of standard, trusted tools. By leveraging a legitimate Google Doc and a standard Google feature, the campaign appeared more credible to the targets. Huntress revealed the scheme after one of its researchers pretended to fall for the scam to gather intelligence on the hacker’s methods.

In the observed interactions, the hacker communicated in what Huntress described as broken English, asking if the target had plans to attend a conference and referencing the event allegedly organised by the crypto news website. The specific identity of the news outlet the hacker claimed to represent has not been explicitly named in the available reporting.

The individual behind the account identified by Huntress did not respond to a private message from TechCrunch on X. Google also had not immediately responded to inquiries regarding whether the company had seen this specific campaign or similar ones. This incident adds to a growing list of attacks on security professionals, which have previously included advanced spyware from unknown government hackers and fake profiles used by North Korean state actors.

Continue reading

More from Tech

Read next: Ethernet Cable Length Matters Most at Higher Network Speeds
Read next: Engadget weighs MagSafe against USB-C for MacBook charging
Read next: Essay challenges reported claims of a 10% AI extinction risk