“The Google Doc was more than your typical phishing lure leading to a malicious web page. If an authenticated Google user opened it, a custom Google Apps Script sidebar was presented alongside the document,” Huntress explained.
How the campaign engaged a researcher on X after Black Hat / Def Con
On August 19, Huntress published a blog describing a targeted phishing interaction that began on X after Black Hat and Def Con this summer. A researcher at the security vendor was contacted by a malicious actor who initially posed as CoinDesk's VP and head of marketing and asked for help with a fictitious upcoming conference. The researcher signaled interest — not to participate, the blog says, but to learn how the scam worked — and the attacker escalated the engagement with multiple, staged lures.
Google Doc lure with a custom Google Apps Script sidebar
The first follow-up message delivered a Google Doc framed as a planning document for the fake conference. Rather than a simple link to a web page, the document contained a custom Google Apps Script that presented a sidebar to any authenticated Google user who opened it. The document asked the user to enter an "encryption key" (supplied by the actor in DMs), which appeared to fail when entered. The sidebar then offered two follow-on options—ClickFix-style instructions and a download option—both of which Huntress said were intended to download and execute malicious code.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCounterfeit DocSend installer delivered platform-specific payloads: AMOS, Ledger-targeting implant, and a proxy
When the Google Doc approach did not succeed, the actor pivoted the next day to a second lure, this one disguised as a Dropbox DocSend share that led to a counterfeit DocSend installer. Huntress reported the installer delivered different payloads depending on the target machine. On macOS systems it installed an infostealer identified as AMOS. On Windows systems it installed an implant designed to steal cryptocurrency from Ledger wallets, plus a traffic‑intercepting proxy intended to help the malware evade security software or checks that rely on VirusTotal.
Persistence and pivoting: social media DMs, trusted services, and a funding pretext
Huntress highlighted how the actor combined social media direct messages with trusted document and file‑sharing services to build credibility and sustain engagement. After the two document-based lures failed, the actor again changed tactics and asked whether the researcher knew anyone who wanted funding of up to $1m. Huntress hypothesized this could be another pretext to obtain credentials or personally identifiable information (PII) from the researcher.
What this means for conference-goers, security teams, and researchers
- Conference-goers: Be suspicious of post-conference outreach that routes you to documents or installers, even when the sender appears to be a reputable outlet or a conference partner. Huntress singled out unexpected requests that ask users to run terminal commands, bypass Gatekeeper, install a manual update, or enter a device password as strong indicators of compromise.
- Security teams: Treat interactions routed through trusted platforms—Google Docs, DocSend, Dropbox—as potential vectors, and consider controls that limit the execution of browser-hosted scripts or the installation of unvetted binaries. Huntress advised isolating affected systems, collecting forensic evidence, and considering reimaging after interaction with such lures.
- Researchers and incident responders: Assume credentials and secrets may have been exposed if a user interacted with the lures. Huntress recommended revoking active sessions, resetting passwords, rotating API keys and other secrets on the system, and reviewing cryptocurrency wallets where relevant.
Huntress' account is a compact case study in how a single attacker can layer persuasion, trusted platforms, and platform-native scripting to escalate from conversation to code execution. The actor adapted when one tactic failed, shifting from a scripted Google Doc to a counterfeit installer with platform-specific payloads, then to a funding offer that could extract different data. For anyone returning from a cybersecurity conference, the practical takeaway from Huntress is precise and actionable: treat unexpected document and installer requests as hostile, and follow containment and credential-remediation steps immediately if you or a colleague engaged with them.
Read the original Huntress write-up here: https://www.infosecurity-magazine.com/news/def-con-attendees-persistent/




