Security experts targeted by fake crypto conference in scam to hand over details
Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn.
Security experts have been targeted by a fraudulent crypto conference scam designed to compromise their devices and steal sensitive information, according to security researchers Huntress. The attackers use a fake account on social media to establish contact with attendees of cybersecurity conferences, including Black Hat and DEF CON.
They then convince victims to attend a supposedly organized conference and share a Google Docs file containing "more info." The file's vertical sidebar is presented as a security feature, prompting victims to enter a decryption code. However, this leads to the installation of the AMOS infostealer malware on macOS devices, which can gather browser information, cookies, keychain data, cryptocurrency wallet details, Telegram files, and more.
If the victim does not install the malware, the attackers follow up with another document, falsely claiming to be for Dropbox, which ultimately leads to the same malware download. Huntress advises victims to isolate affected systems, reset credentials, rotate secrets, and review cryptocurrency wallets to prevent further exploitation.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.