After Black Hat and DEF CON, a threat actor posed as a CoinDesk executive and contacted a Huntress researcher on X with a fake conference-planning proposal. The lure led to a Google Doc containing a malicious Apps Script sidebar, fake decryption instructions, and ClickFix-style commands. A second document impersonated DocSend and delivered different payloads to macOS and Windows users, including AMOS, NetSupport RAT, a Ledger implant, and a traffic-intercepting proxy. The campaign shows how attackers can turn trusted collaboration tools into malware delivery systems while adapting payloads to the victim’s platform. Check out our upcoming Tradecraft Tuesday episode, where we’ll go through this attack in more detail!
The X account messaging our researcher about the "conference," sharing the Google Doc and encryption key