Fake Crypto Conference Lures Security Researchers into Malware Trap

Fake Crypto Conference Lures Security Researchers into Malware Trap

First seen 20 Aug 2026, 09:53 UTC Huntressblog.talosintelligence.comInfosecurity-MagazineScworldhaveibeensquatted.com+8 54.8

Article Content

Browse articles
ThreatCluster

A malicious campaign targeted cybersecurity professionals following the Black Hat and DEF CON conferences, using social engineering tactics. Attackers impersonated a CoinDesk executive and sent Google Docs that appeared to be planning documents for a fake conference. The documents contained a Google Apps Script sidebar that prompted users for a decryption key, leading to malware installation. The malware included an infostealer for macOS and a remote access tool for Windows. This campaign highlights the vulnerability of security experts to sophisticated phishing attacks. The attackers leveraged familiar platforms to build credibility and maintain engagement with their targets. The incident underscores the ongoing threat of social engineering in the cybersecurity landscape.

Key Points: • Attackers impersonated a CoinDesk executive to lure cybersecurity professionals. • Malware was delivered via Google Docs with a fake decryption key prompt. • The campaign targeted both macOS and Windows users with different malware payloads.

Timeline

2026-08-09
Phishing campaign initiated post-DEF CON
Attackers began targeting attendees of Black Hat and DEF CON using social media and Google Docs.
Huntress
2026-08-19
Huntress publishes details of the attack
Huntress detailed the social engineering tactics used in the phishing campaign against its researcher.
Huntress
2026-08-20
Multiple reports confirm the phishing campaign
Several cybersecurity outlets reported on the tactics and implications of the phishing campaign targeting security researchers.
Techcrunch