Key takeaways
- A hacker impersonated a cryptocurrency news outlet to target security researchers on X using both public replies and private direct messages, timing the campaign around Black Hat and Def Con conferences in mid-August.
- The attack used Google Docs with a fake encryption sidebar powered by Google App Script, tricking targets into entering a decryption key that would trigger multi-stage malware installation.
- The campaign prepared platform-specific payloads including an infostealer for macOS, a weaponized remote desktop tool for Windows, and a fake Ledger cryptocurrency wallet installer.
- Huntress uncovered the scheme after one of its researchers engaged with the attacker to trace the full infection chain, revealing a recurring threat pattern against security professionals.
Cybersecurity professionals, whose primary role involves identifying and exposing hacking campaigns, became the targets of a sophisticated social engineering attack that weaponized a fake cryptocurrency conference as its centerpiece. The campaign struck during the annual Black Hat and Def Con hacking conferences in mid-August, demonstrating how attackers continue to evolve their methods against some of the most security-aware individuals in the industry.
Targeting Researchers at Major Security Conferences
A hacker posing as a representative from a prominent cryptocurrency news outlet systematically approached security researchers through X, the social media platform formerly known as Twitter. The attacker employed both public replies to tweets and private direct messages as initial contact vectors, establishing a foothold before deploying more sophisticated social engineering tactics.
The social media approach on X
In communications reviewed by researchers, the attacker used broken English to inquire whether targets planned to attend upcoming conferences. Rather than appearing as an obvious threat, the messages mimicked legitimate industry networking—researchers regularly discuss conference attendance and professional gatherings on X. This normalization of the conversation made targets more receptive to subsequent communications and requests. The attacker’s broken English, rather than drawing suspicion, aligned with how non-native English speakers commonly participate in global cybersecurity communities, further obscuring the threat.
Impersonating an established crypto news outlet
By claiming to represent a recognized cryptocurrency news organization, the hacker leveraged the inherent credibility of an established media brand. This impersonation was not accidental—it was a calculated choice to increase trust and perceived legitimacy. Researchers from Huntress, the security firm that investigated and publicly documented the campaign on Wednesday, noted that the connection to a familiar industry publication made subsequent requests for action significantly more likely to be honored by targets.

Google Docs as a Malware Delivery Vehicle
Following initial contact establishment, the attacker sent what appeared to be a planning document for the fake conference. The delivery mechanism was Google Docs, a platform where security researchers regularly collaborate and share sensitive materials. By disguising the malicious payload within a service already trusted across the security industry, the attacker bypassed traditional defenses and exploited users’ legitimate use of Google’s platform.
Creating a convincing fake encryption interface
The Google Doc displayed a sidebar prominently marked to suggest that the document was encrypted or otherwise protected. This sidebar represented the campaign’s critical deception point. If victims accepted the premise that accessing the document required decryption, they would be more likely to follow the attacker’s next instruction: entering a decryption key. Unbeknownst to the targets, this key was not for encryption at all—it was the first component in a multi-stage malware infection process.
Leveraging Google App Script for technical deception
To construct the convincing fake sidebar, the attacker employed Google App Script, a development platform specifically designed to customize Google Docs interfaces through menus and sidebars. By using Google’s own extension capabilities, the malicious interface appeared to originate from Google itself, rather than from an external or suspicious source. This use of legitimate platform features to deliver malicious instructions represented a form of abstraction attack, where normal functionality becomes a trojan horse for compromise.
Multi-Platform Malware Arsenal
The campaign was architected to compromise targets regardless of their computing platform, with the attacker preparing distinct payloads tailored to different operating systems. The post-decryption delivery mechanism ensured that once a target entered the fake decryption key, the infection would proceed based on their system type.
Three distinct malware variants for different systems
Huntress researchers identified three separate malicious payloads prepared for delivery through this campaign. Targets using Apple computers would receive an infostealer—malware specifically designed to capture sensitive data from the compromised system. This type of malware typically exfiltrates passwords, cryptocurrency keys, private keys, and other valuable credentials from the infected machine. Windows users faced a different payload: a remote desktop tool that had been repurposed as malware. Remote desktop applications normally allow legitimate users to access their computers remotely; when weaponized by attackers, they provide unauthorized access and control over the compromised machine, effectively giving the attacker a foothold for further exploitation. The campaign also included a fake installer for Ledger, the popular cryptocurrency hardware wallet. This payload specifically targeted professionals in cryptocurrency and blockchain industries, likely aiming to compromise wallet credentials or private keys that could unlock significant cryptocurrency holdings.
How Huntress Uncovered the Campaign
Security researchers at Huntress identified the campaign when one of their own staff became a target of the attack. Rather than immediately blocking or reporting the malicious contact, the researcher made a strategic decision to engage with the attacker and trace the entire infection chain to understand its full scope.
By pretending to cooperate with the hacker and progressing through the infection steps without actually executing the malware, the Huntress researcher gathered comprehensive information about the campaign’s mechanics, payload delivery sequences, and multi-stage infection process. This investigation allowed the firm to map the entire attack infrastructure before disclosing details. The decision to engage with the threat rather than immediately reporting it provided the security community with detailed intelligence about the campaign’s operation.
A Recurring Threat Against Security Professionals
This campaign is not an isolated incident. The targeting of security researchers and cybersecurity professionals represents a persistent strategy across multiple threat actor categories. Government-sponsored hackers, including those attributed to North Korea, have previously used social media impersonation campaigns to target security professionals. Advanced spyware operations attributed to unknown government actors have similarly focused their efforts on researchers and security experts.
The timing of this campaign to coincide with Black Hat and Def Con is particularly significant. These conferences draw prominent figures from the security industry during periods of heightened activity and conference-related networking. An attack timed to overlap with these events exploits the natural increase in conference discussions and credential-sharing that occurs during these weeks.
When TechCrunch contacted the account identified by Huntress as the campaign’s source, the person behind it did not respond to the inquiry. Google, when asked whether the company had observed this particular campaign or similar attacks using its services, did not immediately provide a response to reporters.
Frequently Asked Questions
How did the attacker initially contact the targets?
The hacker approached security researchers on X using both public replies and private direct messages, claiming to represent a cryptocurrency news outlet and asking about their plans to attend upcoming conferences.
What role did Google Docs play in the attack?
Google Docs served as the delivery mechanism for the malicious payload. The attacker created a fake conference planning document with a sidebar designed to appear encrypted, using Google App Script to make it look legitimate and prompting targets to enter a decryption key.
What types of malware were included in the campaign?
The campaign included three platform-specific payloads: an infostealer for macOS systems to capture sensitive data, a weaponized remote desktop tool for Windows to provide the attacker access, and a fake Ledger cryptocurrency wallet installer targeting wallet users.