Hackers used fake crypto conference to target security researchers

Hackers used fake crypto conference to target security researchers

Researchers said the campaign used legitimate Google Docs to deliver malware targeting macOS and Windows users.

Hackers posing as representatives of a crypto news site targeted cybersecurity professionals with a fake conference invitation designed to deliver malware, according to TechCrunch and security researchers.

Advertisement

The campaign reached targets through public replies and direct messages on X around the Black Hat and Def Con conferences. Huntress detailed the operation after one of its researchers engaged with the attacker to study the approach.

The attacker shared a legitimate Google Doc presented as a conference planning document, using a fake encrypted sidebar and decryption key to persuade the target to continue. Huntress said the next steps could install malware for macOS or Windows.

The campaign reportedly included an infostealer for Apple computers, a repurposed remote-desktop tool for Windows and a fake Ledger crypto wallet installer. 

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Hackers used fake crypto conference to target security researchers
Hackers used fake crypto conference to target security researchers

Researchers said the campaign used legitimate Google Docs to deliver malware targeting macOS and Windows users.

Share

Add us on Google

Hackers posing as representatives of a crypto news site targeted cybersecurity professionals with a fake conference invitation designed to deliver malware, according to TechCrunch and security researchers.

Advertisement

The campaign reached targets through public replies and direct messages on X around the Black Hat and Def Con conferences. Huntress detailed the operation after one of its researchers engaged with the attacker to study the approach.

The attacker shared a legitimate Google Doc presented as a conference planning document, using a fake encrypted sidebar and decryption key to persuade the target to continue. Huntress said the next steps could install malware for macOS or Windows.

The campaign reportedly included an infostealer for Apple computers, a repurposed remote-desktop tool for Windows and a fake Ledger crypto wallet installer. 

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.