PULSE the living trend engine
▲ Peaking Technology

Someone targeted security researchers using a fake crypto conference as a lure

Hackers targeted security researchers attending Def Con and Black Hat using a fake crypto conference lure and Google Docs.

5sources
5articles
3velocity
+0%since first seen
2h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Recent reports from multiple technology and cybersecurity publications detail an active phishing campaign aimed at security researchers who recently attended the Def Con and Black Hat conferences. According to coverage from TechCrunch, SC Media, and Infosecurity Magazine, malicious actors utilized a fake cryptocurrency conference as a primary social engineering lure to target industry professionals. The scheme involves impersonating a CoinDesk executive to deceive victims into opening a malicious Google Doc, which then leverages Google Doc Apps Script to deliver malware. Huntress and other security sources have documented the technical mechanics of this post-Def Con phishing operation, highlighting how persistent the campaign has been since the conclusion of the major security events. Publications such as SC Media and TechCrunch emphasize the specific vector utilized in the attack, focusing heavily on the Google Doc lure and the malicious use of Apps Script for malware delivery.

Huntress provides granular technical breakdowns of the delivery mechanism, while Bitcoin World and Infosecurity Magazine highlight the social engineering tactics, including the impersonation of a prominent cryptocurrency media executive. The coverage consistently connects the timing of the campaign to the aftermath of the Def Con and Black Hat hacker conventions, noting that conference attendees were specifically singled out by the persistent threat actors for this targeted phishing operation. This trend emerges directly from the high-profile hacker gatherings in Las Vegas, where security researchers routinely congregate, making them prime targets for sophisticated threat actors seeking high-value access. While broader historical campaigns often target general enterprise users, this specific operation is tailored specifically to researchers attending Def Con and Black Hat. Coverage does not yet specify the total number of compromised individuals or the definitive identity of the threat group behind the fake crypto conference infrastructure, leaving many questions about the ultimate origin and attribution of the attacks unanswered.

Observers and security teams will continue monitoring the aftermath of the Def Con and Black Hat phishing campaign to see if further technical details regarding the malicious Google Doc Apps Script emerge. Coverage does not yet specify whether additional outlets will identify new victims or if platform providers like Google will take further action against the specific scripts utilized. Readers should consult ongoing updates from technical reporting organizations like Huntress and TechCrunch for the latest developments on the fake crypto conference threat.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.

Quick answers

Who was targeted by the phishing campaign?

Security researchers who attended the Def Con and Black Hat conferences.

What lure did the hackers use?

A fake crypto conference featuring the impersonation of a CoinDesk executive and a Google Doc.

Which organizations provided technical analysis of the malware delivery?

Huntress, TechCrunch, SC Media, Infosecurity Magazine, and Bitcoin World covered the campaign.

Coverage (5)

Topics

Related trends

◼ Archived Business 🔮 fades ✓

Fed probe of a16z cuts to core of venture capital

A Department of Justice investigation into Andreessen Horowitz's board seat practices is creating significant uncertainty across the venture capital industry.

1 sources 1 articles v 0 2d ago