Cybersecurity Pros Turn the Tables on Hackers During Def Con Phishing Campaign
Attempting to hack a cybersecurity professional is a high-stakes game that rarely ends well for the perpetrator. A recent campaign targeting experts attending the major Black Hat and Def Con conferences serves as a stark reminder that when you target the industry’s best, you are likely to be caught.
Earlier this month, a threat actor posing as a representative for a prominent crypto news outlet launched a social engineering campaign targeting security researchers via X (formerly Twitter). The attacker utilized a combination of public replies and direct messages, eventually funneling targets toward a malicious Google Doc disguised as an event-planning document.
The Anatomy of the Attack
According to a detailed report published Wednesday by the security firm Huntress, one of their own researchers was targeted. Rather than blocking the account, the researcher played along to document the hacker’s tactics.
The interaction began with the attacker inquiring about the researcher’s conference schedule in broken English, eventually pivoting to a pitch for an exclusive crypto-themed event. To add a veneer of legitimacy, the hacker shared a Google Doc that appeared to be a planning brief.
The document featured a sophisticated sidebar designed to look like a secure, encrypted viewer. The attacker instructed the researcher to enter a “decryption key,” which served as the gateway to a malware delivery system. By exploiting Google App Script—a legitimate platform meant for customizing Google Docs—the hacker created a convincing, interactive user interface that masked malicious intent.
A Multi-Platform Threat
Once the victim interacted with the malicious script, the campaign attempted to deploy various payloads depending on the target’s operating system:
- For macOS: A specialized infostealer designed to scrape sensitive data.
- For Windows: A remote desktop viewing tool repurposed for unauthorized access.
- General target: A fake installer for the Ledger cryptocurrency wallet, aimed at siphoning digital assets.
A Known Pattern
While hackers frequently target cybersecurity experts—ranging from state-sponsored actors to independent cybercriminals—the use of legitimate Google infrastructure made this particular effort more dangerous than typical “spray-and-pray” phishing attempts. By leveraging trusted tools, the attacker was able to bypass initial skepticism that often accompanies unsolicited links.
Despite the sophistication of the ploy, it ultimately failed to compromise the Huntress researcher, who utilized the interaction to expose the attacker’s infrastructure. TechCrunch attempted to contact the individual behind the X account associated with the campaign, but received no response.
Google has not yet provided comment on whether it is tracking this specific campaign or if it intends to implement new restrictions on the use of Google App Script in shared documents. For now, the incident serves as a reminder that even the most seasoned experts must remain vigilant, as malicious actors continue to exploit the very tools we use to facilitate our daily work.
