← Back to Issue

Someone targeted security researchers using a fake crypto conference as a lure

From TechCrunch Daily News · subscribed via aiste.ulozaite@gmail.com · original ↗ · unsubscribe

A hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.


Someone targeted security researchers using a fake crypto conference as a lure TechCrunch

–:–:–:–

🚨 Flash Sale 🚨 Get $100 off your Disrupt 2026 ticket

Save $300 on your Disrupt 2026 ticket: REGISTER NOW.

Close

TechCrunch Desktop Logo

TechCrunch Mobile Logo

Search

Submit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Contact Us

The Google Docs application is seen on a portable device in this photo illustration on December 6, 2017.

Image Credits:Jaap Arriens/NurPhoto / Getty Images

Security

Someone targeted security researchers using a fake crypto conference as a lure

Lorenzo Franceschi-Bicchierai

1:00 PM PDT · August 20, 2026

If you are a malicious hacker, cybersecurity professionals may very well be the worst people in the world to try to hack, as there is a very good chance they are going to catch you.

A person pretending to work for a leading crypto news site targeted several cybersecurity professionals around the time of the Black Hat and Def Con hacking conferences earlier this month. The hacker approached attendees on the social media site X, both via public replies and DMs, and then leveraged Google Docs in an attempt to trick the targets into installing malware, according to researchers. 

On Wednesday, security firm Huntress published a blog post detailing the hacking campaign, which targeted one of its researchers, who pretended to go along with it to learn what the hacker was trying to do. 

In broken English, the hacker asked the researcher if they had plans to attend a conference next, and then mentioned a conference allegedly organized by the crypto news website, according to a screenshot of the conversation.

After that, the hacker shared a legitimate Google Doc that looked like it was a planning document for the fake conference. The document displayed a sidebar designed to make the target think it was encrypted. The goal was to first trick the target into entering a fake decryption key provided by the hacker. That was the first step in a process that would lead to the installation of malware for macOS and Windows, depending on the operating system used by the target, according to Huntress.

To make the sidebar appear real, the hacker used Google App Script, a platform that allows developers to customize the user interface of Google Docs with menus and sidebars, for example.

A screenshot of the Google Doc sent by the hacker to the Huntress researcher.

A screenshot of the Google Doc sent by the hacker to the Huntress researcher.Image Credits:Huntress/Screenshot

The hacker tried to trick Huntress’ researcher into installing an infostealer for Apple computers; a remote desktop viewing tool repurposed as malware for Windows; and a fake installer for the cryptocurrency wallet Ledger.  

The person behind the account identified by Huntress researchers as the hacker did not respond when TechCrunch sent them a private message on X. 

Hackers of all kinds — whether they are unknown government hackers using advanced spyware or North Korean government hackers using fake Twitter profiles — have targeted cybersecurity professionals before. What made this campaign a bit more believable was the use of a legitimate Google Doc and Google feature. 

Google did not immediately respond when TechCrunch reached out asking if the company had seen this or similar hacking campaigns.

Topics

cyberattack, cybercrime, cybersecurity, Google, google docs, malware, Security

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai

Lorenzo Franceschi-Bicchierai

Senior Reporter, Cybersecurity

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio

Event Logo

October 13 – 15

San Francisco

In less than 48 hours, your chance to save up to $300 on your tickets will end!

REGISTER NOW

Loading the next article

Error loading the next article

TechCrunch Logo

© 2026 TechCrunch Media LLC.

Highlights & notes

    Notes