{
  "id": 2387511,
  "title": "Security experts targeted by fake crypto conference in scam to hand over details",
  "url": "https://urgent.news/2026/08/21/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-08-21T13:20:22.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand-over-details"
  },
  "original_language": "en",
  "account": "Security experts have been targeted by a fraudulent crypto conference scam designed to compromise their devices and steal sensitive information, according to security researchers Huntress. The attackers use a fake account on social media to establish contact with attendees of cybersecurity conferences, including Black Hat and DEF CON. They then convince victims to attend a supposedly organized conference and share a Google Docs file containing \"more info.\" The file's vertical sidebar is presented as a security feature, prompting victims to enter a decryption code. However, this leads to the installation of the AMOS infostealer malware on macOS devices, which can gather browser information, cookies, keychain data, cryptocurrency wallet details, Telegram files, and more. If the victim does not install the malware, the attackers follow up with another document, falsely claiming to be for Dropbox, which ultimately leads to the same malware download. Huntress advises victims to isolate affected systems, reset credentials, rotate secrets, and review cryptocurrency wallets to prevent further exploitation.",
  "summary": "Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}