All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Hacker uses fake crypto conference to lure cybersecurity researchers with malware

Created at 20 Aug · 8:26 PM1 source↑ Market-relevant
IN SHORT

A hacker posed as a crypto news site representative to target cybersecurity professionals with malware, using a legitimate Google Doc with a custom sidebar to trick victims into installing malicious software for macOS and Windows.

Who's Involved

Huntress
security firm that detailed the hacking campaign
X
social media platform used by the hacker
Google Docs
platform used to deliver malware
Google App Script
tool used to customize Google Docs interface
Ledger
cryptocurrency wallet targeted by fake installer
Hacker uses fake crypto conference to lure cybersecurity researchers with malware

↳ Why This Matters

This incident demonstrates a sophisticated social engineering tactic targeting cybersecurity professionals, highlighting the evolving methods used by malicious actors to distribute malware and the importance of vigilance even among security experts.

Key facts

  • A hacker targeted cybersecurity professionals using a fake crypto conference as a lure.
  • The attacker approached targets on social media platform X.
  • Google Docs and Google App Script were used to create a deceptive interface.
  • The goal was to trick victims into entering a fake decryption key, leading to malware installation.
  • Malware for both macOS and Windows operating systems was deployed.
  • The targets included an infostealer, a remote desktop tool, and a fake cryptocurrency wallet installer.

A cybersecurity campaign has targeted security professionals by using a fake cryptocurrency conference as a lure. The attacker, posing as an employee of a leading crypto news site, approached potential victims on the social media platform X. Leveraging Google Docs and Google App Script, the hacker created a seemingly legitimate planning document for a non-existent conference. This document featured a sidebar designed to appear encrypted, aiming to trick targets into entering a fake decryption key.

This initial step was part of a larger scheme to install malware on the victims' computers. Depending on the operating system, the hacker attempted to deploy an infostealer for macOS, a repurposed remote desktop tool for Windows, and a fake installer for the Ledger cryptocurrency wallet. Security firm Huntress published details of the campaign, which included one of its own researchers posing as a victim to gather intelligence.

The hacker's use of legitimate Google features and a plausible scenario, combined with broken English, made the attack more convincing. This incident highlights the ongoing efforts by malicious actors to target cybersecurity experts, even when using sophisticated social engineering tactics.

Frequently asked questions

The hacker used a fake cryptocurrency conference, presented through a Google Doc, as a lure to target cybersecurity professionals.

The hacker tricked victims into entering a fake decryption key within a Google Doc, which was the first step in installing malware.

The deployed malware included an infostealer for macOS, a remote desktop tool for Windows, and a fake installer for the Ledger cryptocurrency wallet.

The malware was designed to target both macOS and Windows operating systems.

What Happens Next

01Google has been contacted for comment on the hacking campaign.

How It Developed

A hacker targeted cybersecurity professionals around the Black Hat and Def Con conferences.
The hacker approached targets on X, using public replies and direct messages.
The hacker leveraged Google Docs to attempt to trick targets into installing malware.
Huntress published a blog post detailing the campaign, which targeted one of its researchers.
The hacker used a fake crypto conference as a lure, sharing a Google Doc designed to appear encrypted.
The process involved tricking the target into entering a fake decryption key.
This led to the installation of malware for macOS and Windows.
The hacker attempted to install an infostealer, a remote desktop tool, and a fake Ledger wallet installer.

Sources

T1
Someone targeted security researchers using a fake crypto conference as a lureTechCrunch

Related Stories

Nearly 2,000 Hacked WordPress Sites Used for Malware Distribution
20 Aug · 4:41 PM
Student Thwarts AI's Attempt to Inject Malware into Open-Source Software
20 Aug · 12:06 PM
Grok LLM Exfiltrates User Data Via Encrypted Instructions
20 Aug · 1:06 PM
Alation confirms cyberattack on data software platform
20 Aug · 1:16 PM
People-search service ClarityCheck exposed millions of face images
20 Aug · 1:41 PM