Thursday, August 27, 2026
Tech Beat
Aug 20, 2026, 8:00 PMCybersecurity

Fake Crypto Conference Lured Security Researchers Into Google Docs Malware Trap

A fake crypto conference campaign targeted Black Hat and Def Con researchers on X, using Google Docs to push Windows and Mac malware via a bogus decryptor.

Listen to this briefingAudio briefing

Summary

Around the Black Hat and Def Con conferences earlier in August 2026, an attacker posing as an employee of a leading crypto news site contacted several cybersecurity professionals through public replies and direct messages on X. Huntress said Wednesday that one targeted researcher played along, after the attacker asked about future conference plans and promoted a supposed event organized by the unnamed publication.

The attacker shared a legitimate Google Doc presented as conference planning material. A sidebar built with Google Apps Script falsely suggested the document was encrypted and requested a supplied decryption key, starting a process designed to install operating system specific malware. Huntress said its researcher was offered an Apple infostealer, a remote desktop viewing tool repurposed as Windows malware, and a counterfeit installer for the Ledger cryptocurrency wallet. The genuine Google service and customizable interface made the lure more credible. The identified X account did not answer TechCrunch, and Google did not immediately respond about whether it had observed this or similar campaigns.

Positives

  • A Huntress researcher played along with the attacker, exposing the campaign’s social engineering process and intended payloads.
  • Huntress published its findings Wednesday, giving cybersecurity professionals details of the fake conference and decryption workflow.
  • Screenshots documented the X conversation, conference planning document and deceptive Google Docs sidebar.

Risks & concerns

  • Several cybersecurity professionals were targeted around the Black Hat and Def Con conferences through public X replies and direct messages.
  • Google Docs and Google Apps Script gave the fake encrypted document the appearance of a legitimate, trusted workflow.
  • Apple targets faced an infostealer, while Windows targets faced a remote desktop viewing tool repurposed as malware.
  • A counterfeit Ledger wallet installer added cryptocurrency theft risk to the campaign’s cross-platform payloads.
  • The identified X account did not answer TechCrunch, and Google did not immediately address whether it had seen similar attacks.
Primary sourceTechCrunchhttps://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate