Fake Crypto Conference Lure Used Against Security Researchers

Huntress has documented a campaign that targeted cybersecurity professionals around the Black Hat and Def Con conferences using a fake cryptocurrency event, social-engineering messages on X and a legitimate Google Doc. The attacker posed as a worker for a prominent crypto news site and contacted potential targets through public replies and direct messages.
One Huntress researcher engaged with the operator to observe the technique. In messages written in broken English, the attacker asked about conference plans and proposed an alleged event organised by the crypto news outlet. The contact then shared a Google document presented as a planning document for that event.
A legitimate document used as the delivery path
The document itself was real, but it contained a sidebar intended to look like an encryption feature. The victim was meant to enter a purported decryption key supplied by the attacker. Huntress said this was the opening step in a chain designed to prompt malware installation on either macOS or Windows.
The sidebar was built with Google Apps Script, a platform that lets developers customise Google Docs interfaces with elements such as menus and sidebars. That use of a genuine Google capability gave the lure added credibility while moving the malicious interaction into a familiar collaboration environment.
Malware paths differed by operating system
Huntress said the operator attempted to deliver an infostealer to Apple computer users. For Windows targets, the campaign used a remote desktop viewing tool repurposed as malware. It also attempted to distribute a fake installer for the Ledger cryptocurrency wallet.
The case reflects a recurring pattern in which attackers target people working in cybersecurity, while adapting trusted brands, platforms and professional events to make their contact appear plausible. A related crypto-focused operation used fake recruiting outreach and macOS malware in fake recruiting outreach and macOS malware, showing how professional engagement can be turned into an initial access route.
Practical implication for security teams
Businesses should treat unsolicited invitations, shared documents and software-installation prompts as separate verification points, even when the document is hosted by a recognised service. Teams can independently confirm an organiser and event, scrutinise unusual document sidebars or scripts, and avoid entering supplied keys or installing software from an unverified outreach flow. These checks help prevent trusted collaboration tools from becoming the path to malware execution.

