{"id":17929,"date":"2026-08-20T09:40:56","date_gmt":"2026-08-20T09:40:56","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17929"},"modified":"2026-08-20T09:40:56","modified_gmt":"2026-08-20T09:40:56","slug":"pretend-crypto-exec-used-booby-trapped-google-doc-to-goal-safety-researcher-after-def-con","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17929","title":{"rendered":"Pretend Crypto Exec Used Booby-Trapped Google Doc to Goal Safety Researcher After DEF CON"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A risk actor impersonating a senior govt at a well known cryptocurrency media outlet tried to contaminate a Huntress researcher with malware within the days following this yr\u2019s Black Hat and DEF CON conferences, in line with new analysis from the safety vendor.<\/p>\n<div class=\"jeg_ad jeg_ad_article jnews_content_inline_ads  \">\n<div class=\"ads-wrapper align-right \"><a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/bit.ly\/jnewsio\" aria-label=\"Visit advertisement link\" target=\"_blank\" rel=\"nofollow noopener\" class=\"adlink ads_image align-right\"><br \/>\n                                    <img decoding=\"async\" class=\"lazyload\" src=\"https:\/\/itsecguru.dessol.com\/wp-content\/uploads\/2018\/08\/ad_300x250.jpg\" alt=\"\" data-pin-no-hover=\"true\"\/><br \/>\n                                <\/a><\/div>\n<\/div>\n<p>The marketing campaign started on X (previously Twitter), the place an account impersonating the chief despatched a direct message to the researcher on 9 August, utilizing a fabricated story about planning an upcoming on-line convention to strike up a dialog. The account reportedly mixed one individual\u2019s photograph with one other individual\u2019s identify and despatched related boilerplate outreach to numerous different convention attendees within the days after the occasions.<\/p>\n<p>Relatively than disengaging as soon as the strategy was recognized as fraudulent, the researcher continued the dialog to look at how the assault would unfold, permitting Huntress to doc all the assault chain from first contact by payload supply.<\/p>\n<h5><strong>A Google Doc with a hidden trick<\/strong><\/h5>\n<p>The lure itself went past a typical phishing hyperlink. The actor shared what seemed to be a planning doc for the fictional convention, hosted on Google Docs. As soon as opened by an authenticated Google account, the doc loaded a customized sidebar constructed with Google Apps Script (the file was named DecryptPanel.html), which prompted the recipient to enter an \u201cencryption key\u201d equipped earlier within the dialog.<\/p>\n<p>Getting into the important thing produced a deliberate \u201cfailure\u201d message, in line with Huntress, which then prompted the goal to work by the sidebar\u2019s \u201cDoc Decryption\u201d choices: a ClickFix-style command to run manually, or a \u201cGuide Replace\u201d obtain. Researchers famous the underlying script validated a restricted set of hard-coded keys, gathered details about the sufferer and their system, despatched exercise updates through Telegram, and branched into separate an infection paths relying on whether or not the goal was utilizing macOS or Home windows. The code reportedly contained feedback written in Russian.<\/p>\n<h5><strong>Two working techniques, two malware paths<\/strong><\/h5>\n<p>On macOS, targets had been directed to run a terminal command that Huntress says pointed to infrastructure caught in a redirect loop on the time of testing, suggesting the payload might not have been totally dwell. An alternate \u201cGuide Replace\u201d path led as an alternative to a GitHub Releases web page internet hosting a disk picture, which requested the consumer to bypass Apple\u2019s Gatekeeper protections to put in it. Evaluation of the disk picture discovered sturdy similarities to Atomic macOS Stealer (AMOS), malware constructed to reap browser credentials, cryptocurrency pockets information, keychain contents, and Telegram recordsdata, earlier than establishing persistence through a scheduled background course of.<\/p>\n<p>Home windows customers following the identical decryption stream had been as an alternative prompted to put in a pretend \u201cGoogle API Connector\u201d replace. Huntress discovered this led to a ClickOnce software signed with a certificates seemingly belonging to a Norwegian firm, which the researchers imagine was stolen or fraudulently obtained. As soon as put in, the applying displayed a spoofed Google Workspace Market interface whereas quietly downloading additional payloads, together with NetSupport RAT, a pretend Ledger cryptocurrency pockets software, and a device able to intercepting community visitors.<\/p>\n<h5><strong>A persistent actor<\/strong><\/h5>\n<p>Huntress mentioned the identical risk actor didn&#8217;t hand over after the preliminary try failed. The next day, the researcher was despatched a second malicious doc, this time disguised as a Dropbox DocSend file share. That doc led to a pretend DocSend installer configured to ship the AMOS stealer to macOS customers, or the identical bundle of Home windows malware described above.<\/p>\n<p>Based on Huntress, the marketing campaign illustrates how attackers are more and more chaining collectively trusted, on a regular basis platforms equivalent to social media, cloud doc instruments and code-hosting websites to construct a convincing, multi-step workflow reasonably than counting on a single suspicious hyperlink.<\/p>\n<p>The findings come amid wider warnings about phishing exercise concentrating on attendees of main safety conferences, with researchers elsewhere on social media flagging related campaigns within the weeks following this yr\u2019s Black Hat and DEF CON in Las Vegas.<\/p>\n<p>Huntress has printed the total technical breakdown of the marketing campaign, together with indicators of compromise, on its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/blog\/defcon-phishing-google-doc-malware\">weblog<\/a>.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A risk actor impersonating a senior govt at a well known cryptocurrency media outlet tried to contaminate a Huntress researcher with malware within the days following this yr\u2019s Black Hat and DEF CON conferences, in line with new analysis from the safety vendor. The marketing campaign started on X (previously Twitter), the place an account [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17931,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10240,10137,662,10136,10241,8898,67,81,3052,211,70],"class_list":["post-17929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-boobytrapped","tag-con","tag-crypto","tag-def","tag-doc","tag-exec","tag-fake","tag-google","tag-researcher","tag-security","tag-target"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17929"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17929\/revisions"}],"predecessor-version":[{"id":17930,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17929\/revisions\/17930"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17931"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-20 12:35:48 UTC -->