Security Researchers Targeted by Fraudulent Cryptocurrency Conference Scam
Cybersecurity experts are frequently perceived as primary targets for cybercriminals since they possess the knowledge to uncover illicit activities.
Recently, an individual disguised as a reputable cryptocurrency news source attempted to mislead numerous cybersecurity professionals during the Black Hat and Def Con hacking conferences that took place earlier this month. This person reached out to participants using the social media platform X, employing both public posts and direct messages to entice them into downloading malware via Google Docs, according to research findings.
On Wednesday, the cybersecurity firm Huntress published a blog post analyzing this hacking scheme and highlighted one of its researchers who interacted with the hacker to assess their intentions.
In a conversation captured in a screenshot, the hacker, who communicated in broken English, asked if the researcher would be attending any upcoming events and mentioned a conference purportedly organized by the cryptocurrency news outlet.
The hacker then shared a meticulously crafted Google Doc that appeared to detail the agenda for the fabricated conference. This document featured a sidebar designed to imitate encryption, prompting the victim to enter a fake decryption key provided by the hacker. This action initiated a chain of events that could result in the installation of malware on either macOS or Windows systems, as indicated by Huntress.
To enhance the sidebar’s appearance, the hacker utilized Google App Script, a tool that allows users to customize the Google Docs interface with additional menus and sidebars.

The hacker aimed to mislead the Huntress researcher into installing different types of malware, including a tool crafted to steal information from Apple devices, remote desktop software disguised as Windows malware, and a counterfeit installer for the Ledger cryptocurrency wallet.
When TechCrunch tried to reach out to the account linked with the hacker via a direct message on X, there was no reply.
Historically, cybersecurity professionals have faced attacks from hackers, whether through anonymous government operatives with advanced spyware or state-backed actors from North Korea using fake Twitter accounts. However, this particular scheme distinguished itself by employing a legitimate Google Doc and a valid Google feature, which added an extra layer of authenticity.
TechCrunch contacted Google to inquire if they were aware of this hacking operation or similar incidents but did not receive a prompt response.
When you make purchases through links in our articles, we may earn a small commission. This does not affect our editorial independence.


