A hacker posing as a representative of a leading cryptocurrency news outlet attempted to target cybersecurity professionals around the time of the Black Hat and Def Con hacking conferences this month. The attacker approached attendees on the social media platform X through both public replies and direct messages, according to a blog post published Wednesday by security firm Huntress. The campaign ultimately aimed to trick victims into installing malware on their devices.

Huntress said one of its researchers was targeted and pretended to go along with the scheme to understand the hacker’s methods. In broken English, the attacker asked the researcher about attending a future conference and referenced an event allegedly organized by the crypto news website. The hacker then shared a legitimate Google Doc that appeared to be a planning document for the fake conference, complete with a sidebar designed to make the target believe it was encrypted.

The document’s sidebar was built using Google App Script, a platform that lets developers customize Google Docs interfaces with menus and sidebars. The goal was to get the target to enter a fake decryption key provided by the hacker, which served as the first step in a process leading to malware installation. Depending on the target’s operating system, the attacker attempted to install an infostealer for Apple computers, a remote desktop viewing tool repurposed as malware for Windows, and a fake installer for the cryptocurrency wallet Ledger.

The X account identified by Huntress researchers as belonging to the hacker did not respond when TechCrunch sent a private message. This campaign follows a broader pattern of hackers targeting cybersecurity professionals, including unknown government hackers using advanced spyware and North Korean government hackers using fake Twitter profiles. What made this attempt more believable, according to Huntress, was the use of a legitimate Google Doc and a real Google feature.

Google did not immediately respond when TechCrunch asked whether the company had seen this or similar hacking campaigns. The attack took place against the backdrop of the Black Hat and Def Con conferences, which draw large numbers of security researchers and industry professionals each year in the United States. Huntress’s findings highlight the ongoing risk that even security experts face from socially engineered attacks that leverage trusted platforms.

More cybersecurity news from TechManNews.