OTHER

Security Researchers Duped by Fake Cryptocurrency Conference Scam

Experts in cybersecurity are frequently considered prime targets for malicious hackers because they have the means to uncover illegal operations.

Recently, an individual posing as a reputable cryptocurrency news organization targeted several cybersecurity experts during the Black Hat and Def Con hacking conferences that took place earlier this month. This person contacted conference participants via the social media platform X, using both public posts and direct messages in a bid to trick them into downloading malware through Google Docs, according to research findings.

On Wednesday, the cybersecurity firm Huntress published a blog post detailing this hacking operation, focusing on one of its researchers who interacted with the hacker to assess their intentions.

In a conversation captured in a screenshot, the hacker, who communicated in broken English, asked if the researcher planned to attend any upcoming events and mentioned a conference purportedly organized by the cryptocurrency news outlet.

Following this, the hacker shared a meticulously crafted Google Doc that appeared to be an agenda for the fictitious conference. This document included a sidebar designed to simulate encryption, enticing the victim to enter a fake decryption key provided by the hacker. This was the first step in a series of actions that could lead to malware installation on either macOS or Windows devices, as reported by Huntress.

To enhance the sidebar’s design, the hacker employed Google App Script, a tool that allows users to customize the Google Docs interface with additional menus and sidebars.

A screenshot of the Google Doc sent by the hacker to the Huntress researcher.
A screenshot of the Google Doc sent by the hacker to the Huntress researcher.Image Credits:Huntress/Screenshot

The hacker aimed to mislead the Huntress researcher into installing a variety of malware, including an information-stealing tool targeting Apple devices, a remote desktop application masquerading as Windows malware, and a counterfeit installer for the Ledger cryptocurrency wallet.

When TechCrunch attempted to reach out to the hacker’s associated account via a private message on X, there was no reply.

Historically, hackers have targeted cybersecurity professionals, whether by using anonymous government agents with advanced spyware or state-sponsored actors from North Korea employing fake Twitter profiles. However, this scheme was particularly noteworthy due to its reliance on a legitimate Google Doc and a valid Google feature, adding an extra level of credibility.

TechCrunch reached out to Google to inquire if they were aware of this hacking campaign or similar incidents, but there was no immediate response.

When you make purchases through links in our articles, we may earn a small commission. This does not affect our editorial independence.