Hackers weaponized Google Docs to target cybersecurity experts with fake crypto conference lure

The attacker created a legitimate-looking workflow designed to trick targets into running malware.
Huntress researchers described how the campaign layered trusted platforms to build credibility.
Mark

Why would someone go after security researchers specifically? Aren't they the hardest targets?

Mimi

That's exactly why. If you can compromise someone who understands threats, you've got access to their tools, their networks, their contacts. It's a high-value target.

Mark

But this researcher caught it. What made them different?

Mimi

They didn't just delete it. They kept talking to the attacker to see what would happen next. Most people would have stopped at the first red flag.

Mark

The Google Docs part—why use something so legitimate-looking?

Mimi

Because it works. Google Docs is something everyone trusts. You click a link to a shared document every day. The attacker was counting on that muscle memory.

Mark

And the eight-second delay on the fake installer?

Mimi

That's the psychology piece. It makes you think something is actually happening, that the software is loading. By the time you realize nothing worked, the malware is already running.

Mark

So what stops someone from falling for this?

Mimi

Skepticism, mostly. And not being in a hurry. But the attacker was patient—they tried multiple times with different approaches. Eventually someone might have clicked.

  • Security researchers attending Black Hat and Def Con — the world's premier hacker conventions — found themselves the targets of a phishing campaign designed to exploit their own professional credibility.
  • Attackers impersonating a CoinDesk executive sent casually worded direct messages on X, using the cover of a fake cryptocurrency conference to make the approach feel routine rather than threatening.
  • The malicious workflow was built for persistence: when one lure failed, another appeared the next day, each one borrowing the visual language of trusted platforms like Google Docs and Dropbox to suppress suspicion.
  • A carefully engineered eight-to-eleven-second delay was embedded in the fake installer — a psychological sleight of hand designed to mimic a legitimate app launch while malware executed silently beneath it.
  • A Huntress researcher disrupted the operation by playing along rather than disengaging, ultimately exposing a multi-stage attack chain that would have deployed infostealers, remote access tools, and counterfeit crypto wallet software.
  • No infections were confirmed, and the fake account was deleted after CoinDesk staff publicly warned potential targets — a narrow escape credited entirely to one researcher's decision to stay in the conversation.

In the weeks surrounding two of the world's largest hacker conventions, a threat actor turned the tools of everyday digital life — social media, shared documents, file hosting — into a layered trap aimed at the very people trained to dismantle such schemes. By impersonating a trusted media brand and dangling an invitation to a conference that never existed, the attackers sought to compromise the machines of security researchers, a reminder that social engineering preys not on ignorance but on the universal human instinct to trust the familiar. The campaign was ultimately unraveled not by automated defenses, but by a single researcher who chose curiosity over caution and stayed in the conversation long enough to expose the machinery behind it.

A researcher at cybersecurity firm Huntress received what looked like a routine message on X: someone claiming to represent CoinDesk was inviting them to an upcoming digital conference. The grammar was off — "hi there are you have plans attend next conferences?" — but the intent was precise. The sender was impersonating a CoinDesk executive, and the same message had been going out to attendees of Black Hat and Def Con, the two largest hacker conventions in the world, both held in Las Vegas that August. The nonexistent conference was the bait. The goal was credential theft, surveillance software, and machine compromise — aimed squarely at people whose profession is stopping exactly this.

Rather than delete the message, the Huntress researcher kept the conversation going. When they expressed interest, the attacker sent a Google Docs link framed as conference details. The document prompted users to enter an encryption key — a request designed to fail — and when it did, offered two download options, both of which would execute malicious code. The attacker was counting on frustration and curiosity to override judgment.

When that didn't work, the attacker returned the next day with a new document disguised as a Dropbox DocSend share, complete with a counterfeit installer. This version included a deliberate pause of eight to eleven seconds after clicking — long enough to simulate a legitimate app launching, short enough to keep the victim from growing suspicious while malware ran silently in the background.

A successful infection would have delivered different payloads depending on the victim's system: an infostealer for Mac users, a remote desktop tool for Windows users, and a fake Ledger cryptocurrency wallet installer for everyone — a final layer aimed at anyone holding digital assets.

Huntress published its findings on August 19. The campaign illustrated how modern social engineering works not through a single deception but through the stacking of trusted platforms — social media, document sharing, file hosting — into a workflow that looks legitimate at every step. The fake X account was eventually deleted, and CoinDesk staff publicly acknowledged the impersonation to warn others. No successful infections were reported, an outcome owed entirely to a researcher who chose to stay engaged rather than walk away.

A researcher at the cybersecurity firm Huntress received a direct message on X that seemed routine enough: someone claiming to work at CoinDesk, the cryptocurrency news outlet, was inviting them to an upcoming digital conference. The message was casual, almost careless—"hi there are you have plans attend next conferences?"—but it was also a trap.

The attacker was impersonating a CoinDesk executive using a fake account, and the real target was not just this one researcher. Throughout August, the threat actor had been sending similar messages to attendees of Black Hat and Def Con, two of the largest hacker conventions in the world, both held in Las Vegas earlier that month. The bait was always the same: an invitation to a cryptocurrency conference that did not exist. The goal was to harvest credentials, install surveillance software, and compromise the machines of people whose job it is to defend against exactly this kind of attack.

The Huntress researcher recognized the scam immediately but did something smarter than deleting the message. Instead of walking away, they continued the conversation, playing along to understand how the attacker worked. This decision would expose a sophisticated social engineering operation that weaponized some of the internet's most trusted platforms.

When the researcher expressed interest, the attacker sent a Google Docs link promising more information about the conference. The document itself was the delivery mechanism. It prompted users to enter an encryption key—a request that seemed plausible on its surface but was designed to fail. When it did, the page offered two alternatives, both of which would download and execute malicious code onto the victim's computer. The attacker was betting that frustration and curiosity would override caution.

When the researcher still did not bite, the attacker tried again the next day with a new document, this time disguised as a Dropbox DocSend share, complete with a counterfeit DocSend installer. This version was engineered with a psychological flourish: when clicked, it would pause for eight to eleven seconds, creating the illusion that an application was launching while malware ran silently in the background. The delay was meant to keep the victim from realizing anything had gone wrong.

If the attack had succeeded, it would have deployed three different types of malware depending on the victim's operating system. Mac users would have received an infostealer designed to harvest sensitive data. Windows users would have gotten a remote desktop tool repurposed for unauthorized access. And everyone would have been offered a fake installer for Ledger, the popular cryptocurrency wallet—a final layer of deception targeting people who might be holding digital assets.

Huntress published its findings on August 19, and the security community took notice. The campaign revealed how threat actors had learned to layer credibility by combining multiple trusted services—social media, document sharing, file hosting—into a single workflow that looked legitimate enough to fool even security professionals. The fake X account was eventually deleted, and CoinDesk staff members acknowledged the impersonation on social media to warn potential targets. No successful infections have been publicly reported, a small mercy owed entirely to the researcher who chose to stay engaged rather than dismiss the initial message.

The researcher recognised the lure as a scam and did not fall for it, then continued engaging with the actor to better understand the tactics they were using.
— Huntress security platform
By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the malware.
— Huntress analysis
Envie de l'histoire complète ? Lire l'original sur The Star ↗
Nous contacter FAQ