A threat actor impersonating a major cryptocurrency news outlet targeted multiple cybersecurity professionals attending the Black Hat and Def Con hacking conferences earlier this month, according to a blog post published Wednesday by security firm Huntress. The attacker contacted security researchers on the social platform X through both public responses and direct messages, then used Google Docs to attempt installing malware on their systems. The campaign exploited legitimate Google features to make a fraudulent conference invitation appear authentic and encrypted.
The hacker communicated with victims in broken English, asking if they planned to attend an upcoming conference before referencing an event supposedly organized by the crypto news site, according to screenshots of the exchanges. The attacker then distributed a real Google Doc formatted to resemble a planning document for the fake conference. That document included a sidebar interface meant to convince targets the file was encrypted, prompting them to input a bogus decryption key supplied by the hacker — the opening move in a sequence designed to install malware for either macOS or Windows depending on the victim's operating system. To create the convincing sidebar, the threat actor leveraged Google App Script, a platform enabling developers to add custom menus and sidebars to Google Docs interfaces.
According to Huntress, the campaign attempted to deploy an information-stealing program for Apple computers, a remote desktop viewing application repurposed as malware for Windows machines, and a counterfeit installer for the Ledger cryptocurrency wallet. One Huntress researcher who was approached by the hacker pretended to cooperate with the scheme to understand the attacker's methods and objectives. The individual operating the X account that Huntress researchers identified as belonging to the hacker did not respond when TechCrunch contacted them privately on the platform. Google also did not provide an immediate response when TechCrunch asked whether the company had observed this or similar hacking operations.
The report notes that cybersecurity professionals have been targeted by various threat actors in the past, ranging from unknown government hackers wielding advanced spyware to North Korean government operatives using fabricated Twitter profiles. What distinguished this particular campaign was its reliance on a legitimate Google Doc combined with an authentic Google feature, lending the attack unusual credibility. The use of Google App Script to simulate document encryption represented a creative abuse of tools designed for legitimate customization purposes, transforming a trusted platform into a vehicle for social engineering. The timing around major security conferences also provided natural cover, as researchers routinely receive outreach about events and networking opportunities during these gatherings.
The campaign underscores the persistent threat facing security professionals who are themselves high-value targets due to their access to sensitive tools, research, and organizational networks. While the researcher who engaged with the attacker successfully avoided infection by recognizing the scheme, the incident demonstrates how legitimate platforms and realistic social pretexts can lower victims' defenses even among highly trained professionals. The combination of conference-themed lures, trusted Google infrastructure, and direct outreach via social media created multiple layers of apparent legitimacy that might have fooled less vigilant targets. Organizations whose staff attend major industry conferences may need to reinforce protocols around unsolicited event invitations and document-sharing requests, particularly when they involve unusual steps like manual decryption. For security teams, the exploitation of Google's customization features to mimic encryption signals a new variation on social engineering that warrants specific awareness training and detection efforts.

