Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

UK Fraud Cases Hit Record High

August 21, 2026

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

August 21, 2026

New Agent Tesla Malware Variant Boosts Evasion Capabilities

August 21, 2026
Facebook X (Twitter) Instagram
Saturday, August 22
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Def Con Attendees Targeted by Persistent Phishing Campaign
News

Def Con Attendees Targeted by Persistent Phishing Campaign

Team-CWDBy Team-CWDAugust 21, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Attendees of cybersecurity conferences should be on the lookout for malicious outreach following the event, according to a new Huntress blog which details one such interaction.

The post, published on August 19, explained that a researcher for the security vendor was targeted on X following Black Hat / Def Con this summer.

Masquerading as CoinDesk’s VP and head of marketing, the malicious actor first asked for help with a fictitious upcoming conference. 

The researcher spotted the scam but expressed interest to better understand the tactics being used.

Read more on phishing: Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign

The actor subsequently sent the researcher a Google Doc disguised as a planning document for the supposed conference.

“The Google Doc was more than your typical phishing lure leading to a malicious web page. If an authenticated Google user opened it, a custom Google Apps Script sidebar was presented alongside the document,” Huntress explained.

“The document asked the user to enter an ‘encryption key’ (supplied by the actor in DMs), which appeared to fail when entered. The sidebar provided two follow-on options: ClickFix-style instructions and a download option, both intended to download and execute malicious code.”

A Persistent Scammer

The researcher didn’t fall for the malicious Google Doc. But that didn’t stop the threat actor, who followed up the next day with another.

This one was apparently disguised as a Dropbox DocSend share and led to a counterfeit DocSend installer.

The installer delivered different payloads depending on the machine the victim was running. For macOS it was an infostealer known as AMOS. For Windows, it was an implant designed to steal cryptocurrency from Ledger wallets, and a traffic-intercepting proxy designed to help the malware evade security software or checks reliant on VirusTotal.

“Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged,” Huntress explained. “By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the malware.”

When that approach didn’t work, the actor apparently pivoted yet again, by asking the researcher if they knew anyone who wanted funding of up to $1m.

This could have been another pretext to steal credentials or personally identifiable information (PII) from the researcher, they hypothesized.

Advice for Conference-Goers

Huntress advised any recent returnee from a conference to be on the lookout for legitimate-looking messages which lead to a document or installer where the user is asked to take actions that security controls would normally prevent.

“Unexpected requests to run terminal commands, bypass Gatekeeper, install a manual update, or enter a device password are all strong indicators of an attempt to compromise rather than routine troubleshooting in a situation like this,” it concluded.

If any users have interacted with such a message, Huntress advised that they: 

  • Isolate the system from the network
  • Collect relevant forensic evidence and consider reimaging the system
  • Assume that credentials have been compromised
  • Revoke active sessions, reset passwords, and rotate API keys or any other secrets residing on the system
  • Review cryptocurrency wallets if relevant



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
Next Article Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Team-CWD
  • Website

Related Posts

News

UK Fraud Cases Hit Record High

August 21, 2026
News

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

August 21, 2026
News

New Agent Tesla Malware Variant Boosts Evasion Capabilities

August 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Don’t let “back to school” become “back to bullying”

September 11, 2025

A stealthy RAT burrowing deep into Android devices

May 26, 2026

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.