Friday, 21 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 21 August 2026 at 07:07

Hacker used fake crypto conference to try to trick security researchers into installing malware

An unidentified attacker posing as a representative of a crypto news outlet targeted cybersecurity professionals around Black Hat and Def Con, using a fake conference and a Google Doc to attempt malware installation. Security firm Huntress documented the campaign after one of its own researchers played along.

Foto: TechCrunch

Around the time of the Black Hat and Def Con hacking conferences earlier this month, several cybersecurity professionals became targets of a campaign in which an attacker claimed to represent a well-known cryptocurrency news website. The attacker reached out to targets on X, using both public replies and direct messages, before turning to a Google Doc in an attempt to get victims to install malware.

Security firm Huntress published a blog post on Wednesday describing the campaign, which included one of its own researchers among the targets. That researcher pretended to cooperate in order to observe the attacker's methods.

Writing in broken English, the attacker asked the researcher about plans to attend an upcoming conference and mentioned an event supposedly organized by the crypto news site. The attacker then sent a legitimate Google Doc styled to look like a planning document for the fictitious conference. The document included a sidebar designed to give the impression the content was encrypted, with the aim of getting the target to enter a fake decryption key supplied by the attacker — the first step toward installing malware built for either macOS or Windows, depending on the victim's system.

To make the sidebar look authentic, the attacker relied on Google App Script, a tool that lets developers customize Google Docs with features like menus and sidebars. The malware the attacker tried to deliver to Huntress's researcher included an infostealer targeting Apple computers, a remote-desktop tool repurposed for Windows systems, and a fake installer impersonating the Ledger cryptocurrency wallet.

The account Huntress identified as belonging to the attacker did not reply when TechCrunch sent it a private message. Cybersecurity professionals have previously been targeted by various types of hackers, but this campaign stood out for its use of a genuine Google document and feature to appear credible. Google had not responded by the time of publication to TechCrunch's inquiry about whether it was aware of this or similar campaigns.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category