Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
Brief
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the days following this year’s Black Hat and DEF CON conferences, according to new research from the security vendor.
The campaign began on X (formerly Twitter), where an account impersonating the executive sent a direct message to the researcher on 9 August, using a fabricated story about planning an upcoming online conference to strike up a conversation.
The account reportedly combined one person’s photo with another person’s name and sent similar boilerplate outreach to a large number of other conference attendees in the days after the events.
