Fake crypto conference used to target cybersecurity researchers

AI

A threat actor attempted to compromise cybersecurity professionals by luring them with a fabricated cryptocurrency conference around the time major hacking events took place. The attacker initiated contact via the social platform X, employing deceptive outreach strategies.

The scheme relied on legitimate Google Docs integrated with Google App Script to simulate an encrypted workspace sidebar. Targets were tricked into entering a fake decryption key, which served as a delivery mechanism for various platform-specific malware payloads for both Windows and macOS systems.

Security firm Huntress uncovered and detailed the campaign after one of its own researchers was approached and played along to expose the tactics. While targeting security experts is notoriously risky, the abuse of trusted document collaboration tools highlights evolving social engineering threats.

  • Cybersecurity experts were targeted in a social engineering campaign.
  • A nonexistent crypto conference served as the primary lure on X.
  • Attackers weaponized Google Docs and App Script to distribute malware.
  • Custom infostealers and remote tools were prepared for Windows and Mac.

Sources:

Leave a Reply

Your email address will not be published. Required fields are marked *