Post-Conference DMs Deliver Malware Through Google Docs
Huntress says an Aug. 9 phishing run after DEF CON and Black Hat used X direct messages to pose as a CoinDesk executive and steer targets to a malicious Google Doc. The lure was built to feel like ordinary conference follow-up, not a break-in.
If an authenticated Google user opened the document, a custom Google Apps Script sidebar appeared and pushed them toward running malware themselves, first through an “encryption key” prompt and then through download or click-through steps. A second DocSend-themed lure followed and aimed to install AMOS on macOS and NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy on Windows.
The campaign sits inside normal post-event networking, which makes the delivery path credible even to security-aware targets. If your staff uses X, Google Docs, or DocSend for follow-up and recruiting, the exposure is not just the first click: a single accepted lure can hand over credentials, wallet access, or remote control across both Mac and Windows endpoints.