
Source: techcrunch.com
As cybersecurity professionals continue to outsmart malicious hackers, a new campaign has been discovered that attempts to trick them into installing malware using a fake crypto conference as a lure.

The campaign, detailed in a blog post by security firm Huntress, targeted several cybersecurity professionals around the time of the hacking conferences Black Hat and Def Con earlier this month.
The hacker, who pretended to work for a leading crypto news site, approached attendees on social media site X, both via public replies and direct messages. The hacker’s goal was to trick the targets into installing malware, specifically an infostealer for Apple computers, a remote desktop viewing tool repurposed as malware for Windows, and a fake installer for the cryptocurrency wallet Ledger.
The hacker used broken English to ask the target if they had plans to attend a conference next, and then mentioned a conference allegedly organized by the crypto news website. The hacker shared a legitimate Google Doc that looked like it was a planning document for the fake conference, complete with a sidebar designed to make the target think it was encrypted.
To make the sidebar appear real, the hacker used Google App Script, a platform that allows developers to customize the user interface of Google Docs with menus and sidebars, for example. The goal was to first trick the target into entering a fake decryption key provided by the hacker, which would be the first step in a process that would lead to the installation of malware for macOS and Windows.
Huntress’ researcher, who pretended to go along with the campaign to learn what the hacker was trying to do, revealed that the hacker did not respond when TechCrunch sent them a private message on X.
What made this campaign a bit more believable was the use of a legitimate Google Doc and Google feature. Google App Script, used by the hacker to customize the Google Doc’s user interface, is a legitimate platform that allows developers to create custom interfaces for Google Docs.
The use of a legitimate Google Doc and Google feature made the campaign more convincing, as it would be difficult for the target to distinguish between a legitimate document and a phishing attempt. This highlights the importance of being cautious when interacting with unfamiliar documents, even if they appear to be legitimate.
As cybersecurity professionals continue to outsmart malicious hackers, it is essential to remain vigilant and cautious when interacting with unfamiliar documents or messages. The use of legitimate tools and features by malicious hackers can make it difficult to distinguish between a legitimate document and a phishing attempt.
This campaign serves as a reminder of the importance of staying up-to-date with the latest security threats and best practices to avoid falling victim to such attacks.
Online Assistant