Security Researchers Fall Victim to Fake Cryptocurrency Conference Scam
For malicious hackers, cybersecurity professionals can be a significant threat, as they have a strong chance of uncovering illicit activities.
Recently, an individual masquerading as a representative from a well-known cryptocurrency news platform targeted various cybersecurity specialists during the Black Hat and Def Con hacking conferences held earlier this month. This hacker contacted attendees through the social media platform X, using both public exchanges and direct messaging, and attempted to trick them into installing malware via Google Docs, as indicated by researchers.
On Wednesday, the cybersecurity firm Huntress published a blog post detailing this hacking scheme, emphasizing how it specifically aimed at one of its own researchers, who chose to engage in the conversation to understand the hacker’s intentions.
In a conversation captured in a screenshot, the hacker, communicating in broken English, asked whether the researcher intended to attend any upcoming conferences and referenced a conference allegedly hosted by the cryptocurrency news outlet.
Subsequently, the hacker provided a convincingly formatted Google Doc that appeared to serve as a planning document for the fictitious conference. This document included a sidebar designed to simulate encryption, misleading the target into inputting a fake decryption key supplied by the hacker. This was the first step in a sequence of actions that could potentially install malware on either macOS or Windows devices, depending on the targeted system, according to Huntress.
To enhance the sidebar’s appearance, the hacker leveraged Google App Script, a development platform that allows users to customize the Google Docs interface with additional menus and sidebars.

The hacker sought to trick the Huntress researcher into installing several types of malware: an information-stealer targeting Apple devices, a remote desktop tool masked as malware for Windows, and a fake installer for the Ledger cryptocurrency wallet.
The person linked to the account identified as the hacker did not reply when TechCrunch reached out via private message on X.
Hackers, whether operating as anonymous government operatives using advanced spyware or state agents from North Korea deploying fake Twitter identities, have long targeted cybersecurity experts. What distinguished this campaign was the combination of a legitimate Google Doc with an authentic Google feature, providing it with an enhanced level of credibility.
When TechCrunch contacted Google to inquire if the company was aware of this hacking operation or similar occurrences, they did not receive an immediate reply.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


