about 1 month ago
TechCrunch Aug 20, 2026

Someone targeted security researchers using a fake crypto conference as a lure

A hacker impersonating an employee from a prominent cryptocurrency news platform targeted cybersecurity professionals using a fabricated crypto conference as bait. This campaign unfolded around the time of the Black Hat and Def Con security conferences earlier in August 2026. The attacker reached out to potential victims on the social media platform X, both publicly and through direct messages, trying to engage them with a credible-sounding invitation to a fake event.

The hacker then employed Google Docs to deploy malware, sharing a legitimate-looking document purported to be a planning resource for the nonexistent conference. Inside this document was a sidebar, rendered using Google App Script, designed to seem like an encrypted feature, encouraging victims to enter a decryption key given by the attacker. This interaction was just the initial phase of a larger scheme that would lead to malware being installed on the targets' devices, whether they used macOS or Windows.

Huntress, a cybersecurity firm, uncovered the operation after one of their own researchers was singled out and agreed to interact with the hacker to decipher the attack's method. The malware payloads included a macOS infostealer, a remote desktop tool adapted for malicious use on Windows, and a counterfeit installer for a Ledger crypto wallet. Despite attempts to establish contact, the individual behind the deceptive X account did not respond to inquiries from TechCrunch.

This scheme highlights a sophisticated tactic by threat actors who exploit trusted platforms like Google Docs to trick savvy security experts. It joins a growing list of operations targeting cybersecurity professionals, a group typically difficult to deceive due to their vigilance. Google has not commented on the incident, leaving questions about whether it has been involved in containment efforts or detected similar campaigns using its services.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.