{"id":258643,"date":"2026-08-20T20:00:00","date_gmt":"2026-08-20T20:00:00","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/20\/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure-techcrunch\/"},"modified":"2026-08-20T20:00:00","modified_gmt":"2026-08-20T20:00:00","slug":"someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/20\/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure-techcrunch\/","title":{"rendered":"Someone targeted security researchers using a fake crypto conference as a lure | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good chance they are going to catch you.<\/p>\n<p class=\"wp-block-paragraph\">A person pretending to work for a leading crypto news site targeted several cybersecurity professionals around the time of the hacking conferences Black Hat and Def Con earlier this month. The hacker approached attendees on social media site X, both via public replies and DMs, and then leveraged Google Docs in an attempt to trick the targets into installing malware, according to researchers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">On Wednesday, security firm Huntress <a rel=\"nofollow noopener\" href=\"https:\/\/www.huntress.com\/blog\/defcon-phishing-google-doc-malware\" target=\"_blank\">published a blog post<\/a> detailing the hacking campaign, which targeted one of its researchers, who pretended to go along with it to learn what the hacker was trying to do.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In broken English, the hacker asked the researcher if they had plans to attend a conference next, and then mentioned a conference allegedly organized by the crypto news website, according to a screenshot of the conversation.<\/p>\n<p class=\"wp-block-paragraph\">After that, the hacker shared a legitimate Google Doc that looked like it was a planning document for the fake conference. The document displayed a sidebar designed to make the target think it was encrypted. The goal was to first trick the target into entering a fake decryption key provided by the hacker. That was the first step in a process that would lead to the installation of malware for macOS and Windows, depending on the operating system used by the target, according to Huntress.<\/p>\n<p class=\"wp-block-paragraph\">To make the sidebar appear real, the hacker used <a rel=\"nofollow noopener\" href=\"https:\/\/developers.google.com\/apps-script\/guides\/docs\" target=\"_blank\">Google App Script<\/a>, a platform that allows developers to customize the user interface of Google Docs with menus and sidebars, for example.<\/p>\n<figure class=\"wp-block-image size-full\"><figcaption class=\"wp-element-caption\"><span class=\"wp-element-caption__text\">A screenshot of the Google Doc sent by the hacker to the Huntress researcher.<\/span><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>Huntress\/Screenshot<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The hacker tried to trick Huntress\u2019 researcher into installing an <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#infostealers\" target=\"_blank\" rel=\"noopener\">infostealer<\/a> for Apple computers; a remote desktop viewing tool repurposed as malware for Windows; and a fake installer for the cryptocurrency wallet Ledger.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" href=\"https:\/\/x.com\/HartmansDoeke\" target=\"_blank\">The person<\/a> behind the account identified by Huntress researchers as the hacker did not respond when TechCrunch sent them a private message on X.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Hackers of all kinds \u2014 be them <a href=\"https:\/\/techcrunch.com\/2025\/10\/21\/apple-alerts-exploit-developer-that-his-iphone-was-targeted-with-government-spyware\/\" target=\"_blank\" rel=\"noopener\">unknown government hackers<\/a> using advanced spyware, or <a rel=\"nofollow noopener\" href=\"https:\/\/blog.google\/threat-analysis-group\/new-campaign-targeting-security-researchers\/\" target=\"_blank\">North Korean<\/a> <a rel=\"nofollow noopener\" href=\"https:\/\/arstechnica.com\/information-technology\/2023\/03\/security-researchers-are-again-in-the-crosshairs-of-north-korean-hackers\/\" target=\"_blank\">government hackers<\/a> using fake Twitter profiles \u2014 have targeted cybersecurity professionals before. What made this campaign a bit more believable was the use of a legitimate Google Doc and Google feature.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Google did not immediately when TechCrunch reached out asking if the company had seen this hacking campaign, or similar ones.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/08\/20\/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good chance they are going to catch you. A person pretending to work for a leading crypto news site targeted several cybersecurity professionals around the time of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":258644,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-258643","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/258643","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=258643"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/258643\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/258644"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=258643"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=258643"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=258643"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}