← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 17, 2026 · 05:46via CyberPress

Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT

Brief

A targeted fake-job campaign compromised a cryptocurrency organization after an employee was approached through LinkedIn while changing jobs.

The attacker posed as a recruiter for a fictitious Web3 protocol, arranged interviews through Calendly, and sent a technical assessment disguised as a Google Sheet.

The assessment page was hosted through Google Apps Script and used genuine Google assets, making it look like a normal Workspace document.

It displayed a “Candidate Verification” prompt and a fake connector error, GAPI-CON-212. Victims were told they needed to install a Google API helper to continue.

That helper was not legitimate. It was a signed Microsoft ClickOnce application called GapiUpdate. application, hosted on gapidriver[. ]com.

Once opened, the installer used Windows ClickOnce components, including rundll32. exe , dfshim. dll , and dfsvc.

Read more on CyberPress