Particle.news
Download on the App Store

Threat Actor Used Fake Crypto Executive and Booby‑Trapped Google Doc to Target Security Researcher

Huntress says its technical report shows the attacker chained social media, a Google Apps Script sidebar and trusted file hosts to deliver separate macOS and Windows malware and has published IOCs and recovery guidance.

Overview

  • A malicious account on X impersonated a CoinDesk marketing executive to contact a Huntress researcher after Black Hat and DEF CON and then sent a Google Doc that triggered the attack workflow.
  • When opened by an authenticated Google user the document launched a custom Google Apps Script sidebar that asked for an “encryption key” and offered a ClickFix‑style command or a download intended to install malware.
  • The macOS path pointed to a disk image that resembled the AMOS infostealer, which can harvest browser data, keychain items, crypto wallets and Telegram files, and the Windows path used a ClickOnce installer that fetched NetSupport RAT, a fake Ledger wallet app and a traffic‑intercepting tool.
  • Researchers found the ClickOnce binary was signed with a certificate tied to a Norwegian company that Huntress believes was stolen or fraudulently obtained, and the actor sent a second DocSend‑style lure the next day when the first attempt failed.
  • Huntress published a full technical breakdown with indicators of compromise and advises recent conference attendees to isolate affected systems, collect forensic evidence, assume credential compromise, rotate secrets and review cryptocurrency wallets.