Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT
Brief
A targeted fake-job campaign compromised a cryptocurrency organization after an employee was approached through LinkedIn while changing jobs.
The attacker posed as a recruiter for a fictitious Web3 protocol, arranged interviews through Calendly, and sent a technical assessment disguised as a Google Sheet.
The assessment page was hosted through Google Apps Script and used genuine Google assets, making it look like a normal Workspace document.
It displayed a “Candidate Verification” prompt and a fake connector error, GAPI-CON-212. Victims were told they needed to install a Google API helper to continue.
That helper was not legitimate. It was a signed Microsoft ClickOnce application called GapiUpdate. application, hosted on gapidriver[. ]com.
Once opened, the installer used Windows ClickOnce components, including rundll32. exe , dfshim. dll , and dfsvc.
