Security Stop-Press : Cyber Security Event Attendees Targeted With Malicious Google Docs
Security Stop-Press : Cyber Security Event Attendees Targeted With Malicious Google Docs
Cyber criminals targeted Black Hat and DEF CON attendees after the events with convincing follow-up messages and malicious Google Docs.
A Huntress researcher was contacted on X by someone posing as a CoinDesk executive and was sent a Google Doc containing a malicious Apps Script sidebar.
Mac users were targeted with AMOS infostealer malware, while Windows users faced NetSupport RAT and other malicious tools.
When the first attempt failed, the attacker reportedly tried again using a fake Dropbox DocSend share.
Huntress warned that major events create a “target-rich environment” because attendees expect new contacts and shared files.
Businesses should remind staff that trusted platforms do not guarantee trusted content, and unexpected requests to install software or paste commands should always be verified.



