Post-DEF CON Phishing Campaign Targets Attendees with Google Docs

Post-DEF CON Phishing Campaign Targets Attendees with Google Docs

First seen 20 Aug 2026, 09:53 UTC Huntressblog.talosintelligence.comwww.volexity.comInfosecurity-Magazine 91% similarity 51.9

Article Content

Browse articles
ThreatCluster

Following the DEF CON and Black Hat conferences, a phishing campaign has emerged targeting attendees. A researcher from Huntress was approached via X by an account impersonating CoinDesk's VP, soliciting help for a fictitious conference. The attacker sent a Google Doc that contained a custom sidebar asking for an 'encryption key' to execute malware. When the researcher did not engage, the attacker followed up with another malicious document disguised as a Dropbox DocSend installer. This second document delivered AMOS stealer to macOS and various malware to Windows users. The campaign highlights the use of familiar platforms to build credibility and trick targets into executing malware. Huntress has advised attendees to be vigilant against such phishing attempts.

Key Points: • Phishing campaign targets cybersecurity conference attendees post-event. • Malicious Google Docs used to deliver malware via custom sidebar. • Attendees advised to be cautious of unexpected requests for sensitive actions.

ThreatCluster AI How this analysis works

Timeline

2026-08-09
Phishing attempt initiated
A researcher was contacted via X by an account impersonating CoinDesk's VP, asking for help with a fictitious conference.
Huntress
2026-08-09
Malicious Google Doc sent
The attacker sent a Google Doc that asked the researcher for an 'encryption key' to execute malware.
Huntress
2026-08-10
Second phishing attempt made
The attacker followed up with another document disguised as a Dropbox DocSend installer delivering multiple malware payloads.
Huntress

Community

Browse all →