• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Pretend Crypto Exec Used Booby-Trapped Google Doc to Goal Safety Researcher After DEF CON

Admin by Admin
August 20, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A risk actor impersonating a senior govt at a well known cryptocurrency media outlet tried to contaminate a Huntress researcher with malware within the days following this yr’s Black Hat and DEF CON conferences, in line with new analysis from the safety vendor.



The marketing campaign started on X (previously Twitter), the place an account impersonating the chief despatched a direct message to the researcher on 9 August, utilizing a fabricated story about planning an upcoming on-line convention to strike up a dialog. The account reportedly mixed one individual’s photograph with one other individual’s identify and despatched related boilerplate outreach to numerous different convention attendees within the days after the occasions.

Relatively than disengaging as soon as the strategy was recognized as fraudulent, the researcher continued the dialog to look at how the assault would unfold, permitting Huntress to doc all the assault chain from first contact by payload supply.

A Google Doc with a hidden trick

The lure itself went past a typical phishing hyperlink. The actor shared what seemed to be a planning doc for the fictional convention, hosted on Google Docs. As soon as opened by an authenticated Google account, the doc loaded a customized sidebar constructed with Google Apps Script (the file was named DecryptPanel.html), which prompted the recipient to enter an “encryption key” equipped earlier within the dialog.

Getting into the important thing produced a deliberate “failure” message, in line with Huntress, which then prompted the goal to work by the sidebar’s “Doc Decryption” choices: a ClickFix-style command to run manually, or a “Guide Replace” obtain. Researchers famous the underlying script validated a restricted set of hard-coded keys, gathered details about the sufferer and their system, despatched exercise updates through Telegram, and branched into separate an infection paths relying on whether or not the goal was utilizing macOS or Home windows. The code reportedly contained feedback written in Russian.

Two working techniques, two malware paths

On macOS, targets had been directed to run a terminal command that Huntress says pointed to infrastructure caught in a redirect loop on the time of testing, suggesting the payload might not have been totally dwell. An alternate “Guide Replace” path led as an alternative to a GitHub Releases web page internet hosting a disk picture, which requested the consumer to bypass Apple’s Gatekeeper protections to put in it. Evaluation of the disk picture discovered sturdy similarities to Atomic macOS Stealer (AMOS), malware constructed to reap browser credentials, cryptocurrency pockets information, keychain contents, and Telegram recordsdata, earlier than establishing persistence through a scheduled background course of.

Home windows customers following the identical decryption stream had been as an alternative prompted to put in a pretend “Google API Connector” replace. Huntress discovered this led to a ClickOnce software signed with a certificates seemingly belonging to a Norwegian firm, which the researchers imagine was stolen or fraudulently obtained. As soon as put in, the applying displayed a spoofed Google Workspace Market interface whereas quietly downloading additional payloads, together with NetSupport RAT, a pretend Ledger cryptocurrency pockets software, and a device able to intercepting community visitors.

A persistent actor

Huntress mentioned the identical risk actor didn’t hand over after the preliminary try failed. The next day, the researcher was despatched a second malicious doc, this time disguised as a Dropbox DocSend file share. That doc led to a pretend DocSend installer configured to ship the AMOS stealer to macOS customers, or the identical bundle of Home windows malware described above.

Based on Huntress, the marketing campaign illustrates how attackers are more and more chaining collectively trusted, on a regular basis platforms equivalent to social media, cloud doc instruments and code-hosting websites to construct a convincing, multi-step workflow reasonably than counting on a single suspicious hyperlink.

The findings come amid wider warnings about phishing exercise concentrating on attendees of main safety conferences, with researchers elsewhere on social media flagging related campaigns within the weeks following this yr’s Black Hat and DEF CON in Las Vegas.

Huntress has printed the total technical breakdown of the marketing campaign, together with indicators of compromise, on its weblog.

Tags: BoobyTrappedCONCryptoDEFDocexecFakeGoogleResearcherSecuritytarget
Admin

Admin

Next Post
California-based startups have raised ~$366B in 2026 thus far throughout 4,000+ firms, greater than triple the whole of all different 49 states mixed (Paul Kiernan/Wall Avenue Journal)

California-based startups have raised ~$366B in 2026 thus far throughout 4,000+ firms, greater than triple the whole of all different 49 states mixed (Paul Kiernan/Wall Avenue Journal)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

California-based startups have raised ~$366B in 2026 thus far throughout 4,000+ firms, greater than triple the whole of all different 49 states mixed (Paul Kiernan/Wall Avenue Journal)

California-based startups have raised ~$366B in 2026 thus far throughout 4,000+ firms, greater than triple the whole of all different 49 states mixed (Paul Kiernan/Wall Avenue Journal)

August 20, 2026
Pretend Crypto Exec Used Booby-Trapped Google Doc to Goal Safety Researcher After DEF CON

Pretend Crypto Exec Used Booby-Trapped Google Doc to Goal Safety Researcher After DEF CON

August 20, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved