Security Researchers Fooled by Fake Cryptocurrency Conference Scam
Cybersecurity professionals can be perceived as a major threat by malicious hackers due to their ability to reveal illegal acts.
Recently, an individual impersonating a well-known cryptocurrency news outlet targeted various cybersecurity experts during the Black Hat and Def Con hacking conferences held earlier this month. This person contacted attendees through the social media platform X, using both public posts and private messages to try and trick them into downloading malware via Google Docs, as highlighted by researchers.
On Wednesday, the cybersecurity firm Huntress published a blog post detailing this hacking attempt, emphasizing how it focused on one of its own researchers, who chose to participate in conversations to assess the hacker’s intentions.
In a conversation captured in a screenshot, the hacker, who communicated in broken English, asked if the researcher planned to attend any upcoming conferences and referenced a conference supposedly hosted by the cryptocurrency news outlet.
The hacker then provided a meticulously designed Google Doc that seemed like a planning document for the fictitious conference. This document had a sidebar crafted to resemble encryption, luring the victim into entering a fake decryption key supplied by the hacker. This was the first step in a series of actions that could potentially install malware on either macOS or Windows devices, depending on the target selected, according to Huntress.
To enhance the sidebar’s aesthetics, the hacker utilized Google App Script, a tool that allows users to customize the Google Docs interface with additional menus and sidebars.

The hacker aimed to trick the Huntress researcher into installing several types of malware, including an information-stealer targeting Apple devices, a remote desktop tool masked as malware for Windows, and a fake installer for the Ledger cryptocurrency wallet.
When TechCrunch tried to reach out to the account linked to the hacker via private message on X, there was no reply.
Hackers have a history of targeting cybersecurity experts, whether acting as anonymous government agents using advanced spyware or state-sponsored operatives from North Korea employing false Twitter identities. However, this campaign was unique in its combination of a legitimate Google Doc with an authentic Google feature, giving it a greater level of believability.
TechCrunch contacted Google to inquire whether the company was aware of this hacking scheme or any similar incidents but did not receive an immediate response.
When you make purchases through links in our articles, we may earn a small commission. This does not affect our editorial independence.


