-
A hacker pretending to work for a crypto news outlet targeted several cybersecurity professionals after Black Hat and Def Con.
-
The attacker used a fake Google Doc to trick researchers into installing hidden malware.
-
Security firm Huntress studied the scheme after one of its own researchers played along to learn the hacker’s tricks.

Hackers keep finding clever new ways to trick even the sharpest security experts. A person recently tried this trick on several cybersecurity professionals. The attacker pretended to represent a well-known crypto news outlet.
This happened right around the time of the Black Hat and DEF CON hacking conferences this month. Cybersecurity experts usually spot scams fast, so tricking them takes real effort. This attacker still gave it a shot, and the story shows how far scammers will go.
The Fake Conference Lure
The hacker reached out to conference attendees through X, a social media platform. Some contact happened through public replies. Other contact happened through private messages. According to researchers, the attacker then used Google Docs to try to install malware on the victims’ devices.
Huntress, a cybersecurity firm, published a blog post about the scheme on Wednesday. The post detailed the entire campaign. One of Huntress’s own researchers became a target. That researcher chose to play along with the scam. The goal was to study exactly how the hacker operated. This gave Huntress details in their report a close look at each step the attacker took.
The hacker’s English contained noticeable errors throughout the conversation. Even so, the attacker asked the researcher about upcoming conference plans. The hacker then mentioned an event supposedly hosted by the crypto news website. A screenshot of the exchange, reviewed by researchers, confirmed how the conversation unfolded, as reported by TechCrunch.
How the Google Doc Trick Worked
After the initial contact, the hacker sent a Google Doc to the researcher. The document looked like a real planning file for the fake conference. It even had a sidebar built to look like an encryption tool. This sidebar aimed to convince the target that the file held protected information.
The attacker then asked the researcher to type in a decryption key. The hacker had supplied that key earlier in the conversation. Entering it was meant to start the next stage of the attack. That next stage would install malware suited to the victim’s device. Huntress found the malware differed depending on whether someone used macOS or Windows.
The hacker built this fake sidebar using Google Apps Script. This tool lets developers add custom menus and features to Google Docs. Because the document itself was genuine, the trick felt more convincing than usual. Huntress noted that this detail made the scam harder to spot at first glance.
Researchers said the hacker pushed three different malicious tools during the attempt. One posed as an information stealer built for Apple computers. Another was a remote desktop tool repurposed to spy on Windows users. The third posed as an installer for Ledger, a popular cryptocurrency wallet brand. Each tool aimed to gain deep access to the victim’s device once installed.
A related macOS campaign uses fake CAPTCHA pages to deliver malware that steals passwords and cryptocurrency wallets. The attack begins with a fraudulent CAPTCHA page that tells visitors to copy a command into Terminal, which then downloads and executes the Atomic macOS Stealer (AMOS) to harvest browser data, Keychain passwords, and crypto wallet information.
Google and the Hacker Stay Silent
TechCrunch attempted to contact the account that Huntress linked to this hacking campaign. That message went out through a private message on X. The account did not respond to the request for comment, according to TechCrunch’s reporting.
This is not the first time hackers have targeted cybersecurity professionals directly. Government-backed hacking groups have used advanced spyware for similar goals before. North Korean state hackers have also used fake social media profiles for similar purposes.
What stood out this time was the use of a real Google Doc. Combining a genuine platform with a custom sidebar made the scheme feel more legitimate than typical scams.
TechCrunch also reached out to Google about the incident. The company did not immediately respond when asked whether it had seen this campaign before. It remains unclear if Google has tracked similar attempts using its Docs platform and App Script feature in the past.
This case is a reminder that even trained security experts remain valid targets. Familiar platforms like Google Docs can still be turned into tools for attacks. Anyone active on professional social networks around major conferences should stay alert.
Unexpected messages that lead to shared documents deserve extra caution, even from seemingly friendly contacts.