Fake Crypto Conference Lure Targeted Security Researchers With Malware

Security researchers were targeted by a fake crypto conference lure that used Google Docs and Apps Script to deliver malware for macOS and Windows.

Aug 21, 2026 - 04:19
 0
Fake Crypto Conference Lure Targeted Security Researchers With Malware
Image Credit: TechAmerica.ai / AI-generated image

Cybersecurity researchers were targeted in a phishing campaign that used a fake cryptocurrency conference and a legitimate Google Doc to try to deliver malware to macOS and Windows computers.

The campaign surfaced around the Black Hat and DEF CON security conferences. According to security firm Huntress, an attacker contacted conference attendees via public posts and direct messages on X, posing as a major cryptocurrency news organisation.

The fake conference led targets to a Google Doc.

One Huntress researcher recognised the outreach as suspicious but continued communicating with the attacker to investigate the campaign. The attacker asked about future conference plans before sharing what appeared to be a planning document for an upcoming event.

The Google Doc itself was real, but it contained a custom sidebar that made portions of the document appear encrypted. The attacker supplied an access key and encouraged the recipient to enter it, beginning a process designed to persuade the target to download or execute malicious software.

The technique relied on Google Apps Script, which legitimately allows developers to extend Google Docs with custom menus, dialogues, and sidebars. Huntress found that the malicious sidebar offered different infection paths depending on whether the target was using macOS or Windows.

Attackers prepared malware for Mac and Windows.

On macOS, one delivery path was associated with the Atomic macOS Stealer (AMO), designed to collect sensitive information from infected computers. A separate lure later presented a counterfeit DocSend installer that could also deliver the stealer.

Windows users faced a different set of payloads. Huntress identified the use of NetSupport Manager, a legitimate remote-administration product that can be repurposed as a remote access trojan, along with a fake Ledger cryptocurrency wallet component and software capable of intercepting network traffic.

The attack was notable for combining familiar services with social engineering rather than relying entirely on an obviously suspicious website. The legitimate Google Docs environment and customised interface could make the malicious instructions appear more credible to a recipient.

Security researchers remain attractive targets.

Cybersecurity professionals have been targeted in sophisticated campaigns before. Google previously documented a campaign aimed specifically at security researchers that used social media identities and malicious material to compromise targets.

North Korean-linked hackers have also previously used fake online personas in attempts to reach security researchers, a tactic documented in earlier reporting on researcher-targeting campaigns.

In the latest case, Huntress’ researcher did not install the malware. The investigation instead exposed how the attacker combined conference-related outreach, trusted online services, and platform-specific malware to compromise people who routinely investigate cyber threats themselves.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.