A malicious hacker, posing as a representative for a cryptocurrency news site, targeted cybersecurity professionals during the Black Hat and Def Con conferences. The hacker’s ploy involved sharing a Google Doc that seemed legitimate but was actually designed to trick researchers into installing malware.
According to a security firm called Huntress, the attacker approached their researcher on social media platform X, initially asking about upcoming plans. When the researcher pretended to comply and expressed interest in a non-existent conference, the hacker shared what appeared to be a planning document for this fake event.
To deceive the target, the hacker utilized Google App Script to create an encrypted sidebar that would prompt the researcher to enter a decryption key. This first step was followed by a process aimed at installing malware specific to macOS and Windows systems.
The campaign used a convincing Google Doc and feature, making it more believable despite its malicious intent. Huntress published their findings on Wednesday, highlighting how the attacker tried to install an infostealer for Apple devices, as well as repurposed remote desktop tools and fake cryptocurrency wallet software.
When TechCrunch reached out, the hacker behind the account did not respond to a private message sent via social media platform X. While this tactic is not new, the use of a legitimate Google Doc adds a layer of sophistication that can make such attacks harder to detect.







