Fake Crypto Conference Lure Targeted Security Researchers With Malware

Security researchers were targeted by a fake crypto conference lure that used Google Docs and Apps Script to deliver malware for macOS and Windows.

Aug 21, 2026 - 04:19
 12
Fake Crypto Conference Lure Targeted Security Researchers With Malware
Image Credit: TechAmerica.ai / AI-generated image

Cybersecurity researchers were targeted in a phishing campaign that used a fake cryptocurrency conference and a legitimate Google Doc to try to deliver malware to macOS and Windows computers.

The campaign surfaced around the Black Hat and DEF CON security conferences. According to security firm Huntress, an attacker contacted conference attendees via public posts and direct messages on X, posing as a major cryptocurrency news organisation.

The fake conference led targets to a Google Doc.

One Huntress researcher recognised the outreach as suspicious but continued communicating with the attacker to investigate the campaign. The attacker asked about future conference plans before sharing what appeared to be a planning document for an upcoming event.

The Google Doc itself was real, but it contained a custom sidebar that made portions of the document appear encrypted. The attacker supplied an access key and encouraged the recipient to enter it, beginning a process designed to persuade the target to download or execute malicious software.

The technique relied on Google Apps Script, which legitimately allows developers to extend Google Docs with custom menus, dialogues, and sidebars. Huntress found that the malicious sidebar offered different infection paths depending on whether the target was using macOS or Windows.

Attackers prepared malware for Mac and Windows.

On macOS, one delivery path was associated with the Atomic macOS Stealer (AMO), designed to collect sensitive information from infected computers. A separate lure later presented a counterfeit DocSend installer that could also deliver the stealer.

Windows users faced a different set of payloads. Huntress identified the use of NetSupport Manager, a legitimate remote-administration product that can be repurposed as a remote access trojan, along with a fake Ledger cryptocurrency wallet component and software capable of intercepting network traffic.

The attack was notable for combining familiar services with social engineering rather than relying entirely on an obviously suspicious website. The legitimate Google Docs environment and customised interface could make the malicious instructions appear more credible to a recipient.

Security researchers remain attractive targets.

Cybersecurity professionals have been targeted in sophisticated campaigns before. Google previously documented a campaign aimed specifically at security researchers that used social media identities and malicious material to compromise targets.

North Korean-linked hackers have also previously used fake online personas in attempts to reach security researchers, a tactic documented in earlier reporting on researcher-targeting campaigns.

In the latest case, Huntress’ researcher did not install the malware. The investigation instead exposed how the attacker combined conference-related outreach, trusted online services, and platform-specific malware to compromise people who routinely investigate cyber threats themselves.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav is a technology writer at TechAmerica.ai, covering artificial intelligence, startups, digital platforms, consumer technology, mobility, and emerging technologies. Her reporting follows major developments across the global technology industry, from AI companies and startup funding to product launches, regulatory investigations, software platforms, and changes affecting large technology markets. At TechAmerica.ai, Shivangi looks beyond the initial announcement to understand what a development means in practice. Her coverage often examines how new technologies, regulatory decisions, and business moves could affect companies, consumers, and the wider industry. She writes for an international audience, focusing on clear, well-researched reporting that gives readers useful context on fast-moving technology stories.