Overview
- A malicious account on X impersonated a CoinDesk marketing executive to contact a Huntress researcher after Black Hat and DEF CON and then sent a Google Doc that triggered the attack workflow.
- When opened by an authenticated Google user the document launched a custom Google Apps Script sidebar that asked for an “encryption key” and offered a ClickFix‑style command or a download intended to install malware.
- The macOS path pointed to a disk image that resembled the AMOS infostealer, which can harvest browser data, keychain items, crypto wallets and Telegram files, and the Windows path used a ClickOnce installer that fetched NetSupport RAT, a fake Ledger wallet app and a traffic‑intercepting tool.
- Researchers found the ClickOnce binary was signed with a certificate tied to a Norwegian company that Huntress believes was stolen or fraudulently obtained, and the actor sent a second DocSend‑style lure the next day when the first attempt failed.
- Huntress published a full technical breakdown with indicators of compromise and advises recent conference attendees to isolate affected systems, collect forensic evidence, assume credential compromise, rotate secrets and review cryptocurrency wallets.