Def Con Attendees Targeted by Persistent Phishing Campaign
An attacker posed as a CoinDesk executive on X to target a security researcher after this year's Def Con and Black Hat conferences. The scam used fake planning documents and a fake file-sharing app to try to install malware that steals passwords or cryptocurrency.
- Report priority
- Medium
- Targets
- AMOS+1 more
How it works
The attacker messaged the researcher on X pretending to be a CoinDesk executive, then sent a Google Doc that opened a custom sidebar asking for a fake 'encryption key' and offering two ways to download and run malicious code, followed a day later by a fake Dropbox DocSend link that led to a bogus installer.
What to do
If you recently exchanged direct messages on X with an unfamiliar contact after a security conference and were sent a Google Doc or a Dropbox DocSend link asking you to enter a code, run a terminal command, or install software, treat any conference-related DM asking you to bypass Gatekeeper, run terminal commands, or enter your device password as an attack. If you interacted with one of these messages, disconnect the device from the network, assume your credentials are compromised, reset passwords, revoke active sessions, rotate API keys, and check any cryptocurrency wallets.
Technical details
Affected software: AMOS, Ledger
An attacker messages a Huntress researcher on X, posing as CoinDesk's head of marketing and asking for help with a made-up conference. The researcher plays along, so the attacker sends a Google Doc that opens a sidebar asking for an 'encryption key,' then offers a ClickFix-style prompt or a download to run malicious code. The researcher does not fall for it, so the next day the attacker sends a fake Dropbox DocSend link that leads to a counterfeit installer built to plant a Mac password-stealing tool or, on Windows, a cryptocurrency wallet thief and a network-traffic proxy meant to dodge security scans.
The lure chain used a weaponized Google Doc with an embedded Google Apps Script sidebar that requested a fake decryption key before offering ClickFix-style terminal instructions or a direct download, followed by a spoofed Dropbox DocSend page serving a trojanized installer. The installer branched by OS: macOS targets received the AMOS stealer, a well-known credential and data theft tool for Mac, while Windows targets received a Ledger-hardware-wallet-targeting cryptocurrency implant paired with a traffic-intercepting proxy designed to interfere with antivirus and VirusTotal-based detection. Huntress attributes the campaign to a single persistent actor who pivoted to a fake $1m funding offer after the malware lures failed.