Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Cybersecurity Classified by Officially
Following Black Hat/DEF CON, a Huntress researcher was targeted by a threat actor who used X DMs and fake security conference planning as a pretext to establish trust before attempting to deploy malware. The researcher recognized the lure as a scam and did not fall for it, but continued engaging with the actor to better understand the tactics they were using.
The campaign targeted macOS and Windows users with different payloads. The macOS path delivered an AMOS infostealer, while the Windows path delivered NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy.
A malicious Google Apps Script supplied by the actor turned a Google Doc into an infection mechanism. The attack presented ClickFix-style instructions alongside a manual download option as a sidebar in the Google Doc.
A second payload imitated a DocSend installer to retrieve either the macOS or Windows payload.
Acknowledgements: Special thanks to Stuart Ashenbrenner, Lindsey Welch, Jamie Levy, and Andrew Brandt for their contributions to this investigation and writeup.
Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans. Attackers are using this activity to make malicious outreach look like just another routine post-conference interaction.
Fresh off the heels of "Hacker Summer Camp," there have been several reports of phishing campaigns that target attendees, with one of our own researchers being among those targeted by threat actors. In this case, on August 9, the X account @HartmansDoeke sent a direct message posing as CoinDesk's VP and Head of Marketing and asking for help with their upcoming conference. The account appears to use one person's image with another person's name. The message ultimately directed the recipient to a Google Doc featuring a custom sidebar designed to guide them through the execution of malware.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/defcon-phishing-google-doc-malware
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/defcon-phishing-google-doc-malware