Security Researchers Fall Victim to Fake Cryptocurrency Conference Scam
Experts in cybersecurity are frequently seen as major targets for malicious hackers because of their ability to reveal unlawful activities.
Recently, an individual posing as a well-known cryptocurrency news outlet targeted various cybersecurity professionals during the Black Hat and Def Con hacking conferences held earlier this month. This person contacted attendees through the social media platform X, using both public posts and direct messages in a bid to trick them into downloading malware via Google Docs, as reported by researchers.
On Wednesday, the cybersecurity firm Huntress published a blog post detailing this hacking scheme, focusing on one of its researchers who engaged in conversations to assess the hacker’s intentions.
In a conversation captured in a screenshot, the hacker, communicating in broken English, asked if the researcher planned to attend any upcoming conferences and mentioned a conference allegedly organized by the cryptocurrency news outlet.
The hacker then shared a meticulously constructed Google Doc that appeared to be an agenda for the fictitious conference. This document contained a sidebar designed to simulate encryption, enticing the victim to input a fictional decryption key provided by the hacker. This was the first step in a series of actions that could potentially lead to malware installation on either macOS or Windows devices, depending on the target, according to Huntress.
To improve the sidebar’s appearance, the hacker employed Google App Script, a tool that allows users to customize the Google Docs interface with additional menus and sidebars.

The hacker aimed to trick the Huntress researcher into installing various types of malware, including an information stealer targeting Apple devices, a remote desktop application disguised as Windows malware, and a fake installer for the Ledger cryptocurrency wallet.
When TechCrunch reached out to the account linked to the hacker via private message on X, there was no reply.
Hackers have a history of targeting cybersecurity professionals, whether as anonymous government agents using advanced spyware or state-sponsored operatives from North Korea employing fake Twitter profiles. However, this particular scheme was notable for its use of a legitimate Google Doc and an authentic Google feature, providing it with a higher level of credibility.
TechCrunch contacted Google to inquire if the company was aware of this hacking operation or similar situations, but did not receive a prompt response.
When you make purchases through links in our articles, we may earn a small commission. This does not affect our editorial independence.


