Fake crypto conference used to target security researchers
Original: Someone targeted security researchers using a fake crypto conference as a lure
Why This Matters
The abuse of legitimate Google infrastructure lowers detection barriers and raises risk for security professionals specifically.
A threat actor posed as a crypto news site staffer and approached cybersecurity professionals on X around the Black Hat and Def Con conferences in August 2026, using a manipulated Google Doc to deliver infostealer and remote-access malware for macOS and Windows.
Security firm Huntress published a blog post on August 20, 2026, detailing a targeted hacking campaign that used a fake cryptocurrency conference as bait to lure cybersecurity researchers into installing malware. The attacker, posing as an employee of a well-known crypto news website, reached out to security professionals on X via public replies and direct messages around the time of the Black Hat and Def Con conferences. The hacker shared a legitimate Google Doc that appeared to be a conference planning document. A sidebar within the document—built using Google App Script, a legitimate developer tool for customizing Google Docs interfaces—was designed to look like an encryption prompt. Targets were asked to enter a fake decryption key, which initiated a multi-step process leading to malware installation. Depending on the victim's operating system, the hacker attempted to deliver an infostealer targeting macOS, a repurposed remote desktop tool for Windows, and a fake Ledger cryptocurrency wallet installer. A Huntress researcher played along with the scheme to document the attack chain. The attacker communicated in broken English. The account identified by Huntress did not respond to TechCrunch's message on X. Google did not immediately comment when contacted.