Someone targeted security researchers using a fake crypto conference as a lure
A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.
Malicious hackers often target cybersecurity professionals, knowing they are likely to spot and stop them. Earlier this month, a hacker impersonating a leading crypto news site reached out to several cybersecurity experts on social media platform X, both publicly and privately. Huntress, a security firm, published a blog post detailing the campaign, which specifically targeted one of its researchers.
The hacker first engaged the researcher in conversation, asking about their plans to attend a forthcoming conference. They then introduced a fake conference allegedly organized by the crypto news website. Accompanying their message was a legitimate Google Doc, designed to mimic a planning document for the nonexistent event. The sidebar in the document was designed to appear encrypted, tricking the target into entering a fake decryption key provided by the hacker.
This initial step was part of a larger process aimed at installing malware on the target's computer, either macOS or Windows. The hacker utilized Google App Script to create a convincing sidebar for the Google Doc. The researcher was offered an infostealer for Apple computers, a repurposed remote desktop viewing tool for Windows, and a fake installer for the Ledger cryptocurrency wallet.
The hacker behind the account did not respond to TechCrunch's inquiry via a private message on X. This particular campaign was made more believable by the use of a legitimate Google Doc and Google feature. Huntress did not immediately respond to a request from TechCrunch regarding the company's knowledge of this or similar hacking campaigns.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.