TechNewsReel
Live

Security researchers targeted by phishing campaign using weaponized Google Docs

Attackers leveraged Google App Script and fake crypto conference lures to deploy malware during Black Hat and Def Con.

TechNewsReel Newsroom · August 20, 2026

Cybersecurity professionals were recently targeted in a sophisticated phishing campaign that used a fake cryptocurrency conference as a lure to deploy malware. The attack specifically targeted high-awareness targets during some of the industry's most prominent annual gatherings.

According to a report from security firm Huntress, the attacker targeted attendees of the Black Hat and Def Con hacking conferences. The campaign was carried out via public replies and direct messages on X. To analyze the attack, a Huntress researcher engaged with the hacker, uncovering a deceptive workflow designed to bypass standard security skepticism.

The Technical Lure

Rather than relying on traditional malicious attachments, the attacker used legitimate Google Docs to establish trust. By utilizing Google App Script, the hacker created a customized, deceptive sidebar within the document that simulated an encrypted file. This sidebar tricked targets into entering a decryption key, a process that ultimately led to the installation of OS-specific malware.

Depending on the victim's operating system, the campaign deployed different payloads. Apple users were targeted with AMOS, an infostealer designed for macOS. Windows users were hit with NetSupport RAT, a repurposed remote desktop viewing tool. Additionally, the attacker utilized a fake Ledger cryptocurrency wallet installer as part of the infection chain.

Context and Industry Risk

Cybersecurity professionals are frequent targets of highly tailored phishing campaigns, often orchestrated by state-sponsored actors, such as those from North Korea, who frequently use fake social media profiles to build rapport. By timing this campaign to coincide with Black Hat and Def Con, the attacker increased the plausibility of a conference-related lure, making the outreach seem like a legitimate networking opportunity among peers.

Why It Matters

This campaign demonstrates a growing trend of weaponizing trusted productivity tools to evade detection. The use of legitimate Google infrastructure makes the phishing attempt significantly more believable and harder for automated security tools to flag than a standard malicious URL. When attackers can successfully manipulate the interface of a trusted platform like Google Docs, even experts in the field are at risk of falling for the deception.

What's Next

Security teams are now monitoring for similar patterns where legitimate cloud services are used to host deceptive interfaces. While the specific identity of the threat actor remains unconfirmed, the use of diverse payloads for different operating systems suggests a coordinated effort to maximize the reach of the campaign across various professional environments.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.