Fake crypto conference lures cybersecurity researchers into malware trap

A malicious actor targeting cybersecurity professionals with a fake crypto conference has been uncovered by security firm Huntress. The campaign took place around the Black Hat and Def Con hacking conferences in early August, according to a blog post published by Huntress on Wednesday.
The attacker posed as an employee of a major crypto news website and approached multiple cybersecurity researchers on social media platform X, using both public replies and direct messages. One of Huntress's researchers was among the targets and decided to play along to learn the attacker's methods.
In broken English, the hacker asked the researcher whether they planned to attend an upcoming conference, specifically mentioning an event allegedly organized by the crypto news outlet. Screenshots of the conversation show the attacker then sharing a legitimate Google Doc that appeared to be a planning document for the fake conference. The document contained a sidebar designed to look like an encryption interface, built using Google App Script, a platform for custom web applications.
The victim was instructed to enter a decryption key provided by the hacker. This was the first step in a multi-stage process that would ultimately lead to the installation of malware. Depending on the target's operating system, the malicious payload was tailored for either macOS or Windows, Huntress reported.
The campaign is notable because it specifically targeted cybersecurity professionals — individuals who are typically hardest to compromise. The attacker's use of a legitimate Google Doc and a fake encryption sidebar demonstrates a sophisticated social engineering approach. Huntress's researcher, who engaged with the hacker to document the scheme, remained safe and did not install any malware. The security firm published the findings to warn other professionals about the ongoing threat.


