
A hacking campaign targeted cybersecurity professionals around the Black Hat and Def Con conferences by impersonating a crypto news organization and using a legitimate Google Doc to deliver malware. Security firm Huntress said one of its researchers was approached on X and deliberately continued the conversation to study the attack.
The attacker contacted targets through public replies and direct messages, asking about upcoming conferences before introducing a supposed event linked to a crypto publication. They then shared a Google Doc designed to look like a legitimate planning document for the fake conference.
A Fake Encryption Prompt Led Toward Malware Installation
Huntress detailed the campaign on Wednesday. The document contained a sidebar that made it appear as though the file was encrypted and required a decryption key supplied by the attacker.
Entering that key was the first step in a process intended to make the victim install malware. Huntress said the payload varied depending on whether the target was using macOS or Windows.
The attacker created the fake sidebar using Google Apps Script, a legitimate platform that allows developers to customize Google Docs with features such as menus and sidebars.
For macOS users, the campaign attempted to install an information-stealing program. Windows users were targeted with remote desktop software repurposed for malicious access, while the attackers also used a fake installer for the Ledger cryptocurrency wallet.
Security Researchers Have Been Targeted Before
Huntress identified an X account it believes was involved in the campaign. The person behind the account did not respond when TechCrunch contacted them privately.
Cybersecurity professionals have previously been targeted by both criminal and state-linked hacking groups. Past campaigns have included government spyware attacks and operations attributed to North Korean hackers using fake social media identities to approach security researchers.
The use of a legitimate Google Docs file and official Google functionality made this campaign more convincing than a basic phishing message. The malicious element came from how the document and scripted interface were used to guide targets toward installing software.
Google had not responded to questions about whether it had observed this campaign or similar misuse of Google Docs at the time of the report.
Featured image credits: Wikimedia Commons
For more stories like it, click the +Follow button at the top of this page to follow us.
