READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Hacker Posed as CoinDesk Executive to Plant Malware on Security Researchers After Black Hat and Def Con

Hacker Posed as CoinDesk Executive to Plant Malware on Security Researchers After Black Hat and Def Con
A scammer impersonating a CoinDesk vice president tried to trick cybersecurity researchers into installing malware using a rigged Google Doc, according to security firm Huntress. One targeted researcher played along instead of falling for it, exposing a multi-stage scheme that used Google Apps Script, fake DocSend installers, and a crypto-wallet-draining payload for Windows.

Cybersecurity researchers make lousy hacking targets. They tend to notice when something's off, and then they write it up for everyone else to read.

That's exactly what happened to a researcher at security firm Huntress this month. According to a Huntress blog post published Wednesday, August 19, an X account under the handle "@HartmansDoeke" contacted the researcher claiming to be CoinDesk's vice president and head of marketing. The account had been replying to multiple attendees of Black Hat and Def Con, the security conferences held in Las Vegas earlier this month, asking to connect.

The researcher spotted the scam immediately. Instead of blocking the account, Huntress says the researcher played along to learn what the attacker was actually trying to do.

The Fake Conference Pitch

The attacker, writing in broken English according to a screenshot obtained by TechCrunch, claimed to be organizing an upcoming conference and asked if the researcher planned to attend. The attacker then sent a Google Doc pitched as a planning document for the event.

That document was not a simple phishing link. Once opened by a user logged into a Google account, it triggered a custom sidebar built with Google Apps Script, a legitimate Google platform that lets developers customize the Docs interface, according to Huntress Principal Security Operations Analyst Jonathan Semon, who spoke with SC Media.

"Google Apps Script is a built-in Javascript platform able to hook into any product in the G-Suite," Semon told SC Media, explaining that the script ships bundled with the document and travels with it when shared.

The sidebar, named "DecryptPanel.html," prompted the victim to enter a "decryption key" supplied by the attacker over direct message. Behind the scenes, Semon said, the script quietly collected the victim's IP address, operating system, city and country, timestamp, and installed browser crypto wallets, using fingerprinting services ipify.org and ipapi.co. That data was routed to the attacker through a Telegram bot, according to Semon.

When the researcher entered the fake key, the document returned an error and offered "update" instructions tailored to the victim's operating system. Both macOS and Windows versions offered a ClickFix-style prompt telling the user to run terminal commands, plus a direct download button, according to SC Media's reporting.

On macOS, Huntress found the terminal command was actually misconfigured, pointing to localhost and causing a redirect loop. The download button instead led to a GitHub Releases page hosting a disk image called "GAPIUpdate.dmg," which walked users through bypassing macOS Gatekeeper security by entering their admin password. Huntress said the resulting malware was "highly consistent" with the Atomic macOS Stealer, known as AMOS, an infostealer built for Apple computers.

A Second Attempt, Then a Money Pitch

The researcher didn't take the bait. According to Infosecurity Magazine's reporting on the Huntress post, the attacker followed up the next day with a second lure: a fake Dropbox DocSend share leading to a counterfeit DocSend installer. Depending on the victim's operating system, that installer delivered AMOS on macOS or, on Windows, an implant designed to steal funds from Ledger cryptocurrency wallets alongside a traffic-intercepting proxy meant to help the malware slip past security tools that check files against VirusTotal.

When neither lure worked, Huntress said the attacker pivoted again, asking the researcher if they knew anyone seeking funding of up to $1 million, a pitch Huntress speculated could have been another attempt to harvest credentials or personal information.

Huntress did not attribute the campaign to a specific hacking group or nation-state, and the operator of the X account did not respond when TechCrunch messaged them for comment. CoinDesk was impersonated but was not itself compromised, and Google did not respond to TechCrunch's request for comment on whether it had seen similar abuse of Apps Script before.

Not the Only North Korea-Style Scheme in the News

Separately, a joint investigation by researchers Mauro Eldritch of BCA LTD, Heiner García of NorthScan, and threat-intelligence firm ANY.RUN, detailed by The Hacker News, shows the reverse version of this problem: state-linked operatives trying to get hired rather than trying to phish. The researchers built a fake DeFi startup called Ballena Azul, posted developer job listings, and say they hired three people they believe were North Korean IT operatives, each of whom submitted identity documents researchers say showed signs of AI editing, including a Google Gemini SynthID watermark on one submitted driver's license photo.

A joint alert issued July 31 warned that North Korean IT workers seek out contract positions specifically to funnel their pay back to state agencies, and flagged forged identity documents as a warning sign for employers. In April, the Justice Department sentenced two U.S.-based facilitators who had helped place North Korean workers at more than 100 companies using at least 80 stolen identities, netting more than $5 million, according to prosecutors.

Neither the CoinDesk impersonation campaign nor the fake DeFi hiring operation has been formally attributed to a specific government by named investigators in these reports. Huntress's advice to conference attendees: be suspicious of any unexpected request to run terminal commands, bypass Gatekeeper, or enter an admin password after opening a shared document. That's not routine troubleshooting. That's the attack.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchSomeone targeted security researchers using a fake crypto conference as a lure
unknown
zamin.uzCybersecurity Experts Targeted in Fake Conference Scam
unknown
scworldBlack Hat/DEF CON attendees targeted in malware scheme with Google Doc lure
unknown
infosecurity-magazineDef Con Attendees Targeted by Persistent Phishing Campaign
unknown
thehackernewsResearchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers