In a bold move that some might call professional suicide, an unidentified attacker recently spent their time targeting the very people most likely to catch them. Around the timing of the high profile Black Hat and Def Con hacking conferences, a bad actor began posing as an employee from a prominent cryptocurrency news outlet to lure cybersecurity experts into a sophisticated trap. Using the social media platform X, the scammer engaged potential victims through direct messages and public replies, attempting to build rapport before introducing a fraudulent event invitation.
The scheme relied on a clever manipulation of trust involving Google Docs. After convincing targets that they were organizing a specialized crypto conference, the hacker shared a link to what appeared to be a legitimate planning document. To add an air of authenticity and urgency, the attacker used Google App Script to create a custom sidebar that mimicked an encryption screen. Victims were prompted to enter a specific decryption key provided by the hacker, a psychological trick designed to lead them toward downloading malicious software tailored to their specific operating system.
Security firm Huntress uncovered the operation after one of its own researchers became a target. Rather than blocking the intruder, the researcher played along to dissect the attack vector. They discovered that the hacker was attempting to deploy various types of malware, including info stealers for Mac users and repurposed remote desktop tools for those on Windows. Some targets were even pushed toward a fake installer for Ledger cryptocurrency wallets, aiming to drain digital assets directly from their devices.
While state sponsored actors often target security professionals using complex spyware, this particular campaign stood out due to its reliance on everyday productivity tools. By leveraging official Google features, the attacker created a facade of legitimacy that could potentially fool even seasoned veterans during the chaos of major industry events. When contacted for comment regarding these deceptive uses of their platform’s scripting capabilities, Google did not provide an immediate response.