Hackers turned a Google Docs feature into a trap for security experts


If successful, the attack would have installed an infostealer for Apple computers, a remote desktop tool repurposed as malware for Windows, and a fake installer for the cryptocurrency wallet Ledger. — Image by rawpixel.com on Magnific

A phishing campaign targeting attendees at two major cybersecurity conventions in Las Vegas earlier this month used an invitation to a bogus cryptocurrency event and an innocent-looking Google Docs link in a ploy to trick victims into downloading malware.

The scheme was uncovered by the cybersecurity platform Huntress after one of its researchers was contacted online by someone posing as the vice president and head of marketing at the legitimate digital media company CoinDesk, which covers the crypto and blockchain industry.

Using a fake account on X, the threat actor sent boilerplate direct messages to people who attended the recent Black Hat and Def Con hacker conventions in Vegas.

“hi there are you have plans attend next conferences?” the attacker wrote in DMs posted by Huntress. “I’m interested invite and happy to connect. can’t find your email.”

The attacker asked its targets if they would be interested in signing up for an upcoming crypto-related online conference that, in fact, did not exist.

“The researcher recognised the lure as a scam and did not fall for it,” Huntress said in its Aug 19 report. The alert employee “continued engaging with the actor to better understand the tactics they were using.”

The campaign included sharing a Google Docs page with “more info” about the nonexistent conference. The document prompted Windows and macOS users to enter an encryption key supplied by the actor, which appeared to fail. A sidebar offered two alternatives, “both intended to download and execute malicious code,” Huntress said.

When the researcher didn’t execute the malware, the attacker followed up the next day with a different document masquerading as a Dropbox DocSend share and a counterfeit DocSend installer.

“Clicking the final button triggered an eight- to 11-second delay designed to make it appear that an application was launching while the malicious loader operated in the background,” reported Redmond Magazine, which describes itself as “the independent voice of the Microsoft IT community.”

If successful, the attack would have installed an infostealer for Apple computers, a remote desktop tool repurposed as malware for Windows, and a fake installer for the cryptocurrency wallet Ledger.

“Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged,” Huntress said. “By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the malware.”

There have been no publicly reported victims of the campaign.

CoinDesk has not issued a statement regarding the attacker who falsely claimed to be a company executive. Individual staff members, however, acknowledged the scheme on social media and alerted potential marks.

The attacker’s fake X account has since been deleted. – Inc./Tribune News Service

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read