In a scheme aimed at top-tier cybersecurity professionals, a hacker masquerading as a staunch figure in crypto journalism targeted attendees of Black Hat and Def Con earlier this month. The attacker used social media—specifically X—to message and publicly engage researchers, offering an invite to a phony conference purportedly backed by a major crypto news outlet. The goal: lure them into downloading malware via a manipulated Google Doc. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
Inside the Deception
After initiating contact with broken English, the malefactor asked whether a researcher planned to attend upcoming security conferences. They then claimed to be organizing one under the name of a respected crypto news brand. To deepen the illusion, they shared what appeared to be an official planning document created in Google Docs. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/)) This document included a sidebar designed to look like an encryption tool, prompting the target to enter a “decryption key” supplied by the attacker—a diversion meant as Step One in installing malware. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
The hovercraft of this attack operated through tools usually seen as benign. It leveraged Google App Script to render the sidebar, making the document feel legitimate. If the deception succeeded, researchers would have first been prompted to enter the fake key, then asked to install either a macOS infostealer, a repackaged remote access tool for Windows, or a counterfeit Ledger wallet installer. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
Who Was Targeted—and What We Know
The campaign’s most visible victim was a researcher employed by Huntress, a security firm that discovered the scheme. Rather than rebuffing the contact outright, the researcher played along to trace the attacker’s strategy. Huntress published these findings in a detailed report. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
Efforts to reach the entity behind the attack via direct message on X were unanswered. The deception in this case wasn’t unique in nature—cybercriminals and hostile state actors have long attempted to ensnare security-focused experts via impersonation or layered social engineering. What sets this instance apart is the use of officially recognizable tools to add credibility. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
Despite attempts to contact Google for comment, no confirmation has emerged from the company about whether it is aware of similar campaigns. ([techcrunch.com](https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/))
This cycle of trickery reminds us that tools like Google Docs, App Script, and sidebars—normally used for collaboration—can be twisted into vectors for exploitation. Even security experts can be taken by surprise when the lure is believable.
What this means: Social engineering remains the linchpin of many cyberattacks. The more authentic the bait, the more successful the hook. Researchers and organizations must scrutinize unexpected invites—even from familiar names—and verify everything: domain names, unexpected documentation, and any calls to install software. As AI-assisted phishing and UI spoofing increase, so too must our guard.