Someone targeted security researchers using a fake crypto conference as a lure
Hackers targeted security researchers attending Def Con and Black Hat using a fake crypto conference lure and Google Docs.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports from multiple technology and cybersecurity publications detail an active phishing campaign aimed at security researchers who recently attended the Def Con and Black Hat conferences. According to coverage from TechCrunch, SC Media, and Infosecurity Magazine, malicious actors utilized a fake cryptocurrency conference as a primary social engineering lure to target industry professionals. The scheme involves impersonating a CoinDesk executive to deceive victims into opening a malicious Google Doc, which then leverages Google Doc Apps Script to deliver malware. Huntress and other security sources have documented the technical mechanics of this post-Def Con phishing operation, highlighting how persistent the campaign has been since the conclusion of the major security events. Publications such as SC Media and TechCrunch emphasize the specific vector utilized in the attack, focusing heavily on the Google Doc lure and the malicious use of Apps Script for malware delivery.
Huntress provides granular technical breakdowns of the delivery mechanism, while Bitcoin World and Infosecurity Magazine highlight the social engineering tactics, including the impersonation of a prominent cryptocurrency media executive. The coverage consistently connects the timing of the campaign to the aftermath of the Def Con and Black Hat hacker conventions, noting that conference attendees were specifically singled out by the persistent threat actors for this targeted phishing operation. This trend emerges directly from the high-profile hacker gatherings in Las Vegas, where security researchers routinely congregate, making them prime targets for sophisticated threat actors seeking high-value access. While broader historical campaigns often target general enterprise users, this specific operation is tailored specifically to researchers attending Def Con and Black Hat. Coverage does not yet specify the total number of compromised individuals or the definitive identity of the threat group behind the fake crypto conference infrastructure, leaving many questions about the ultimate origin and attribution of the attacks unanswered.
Observers and security teams will continue monitoring the aftermath of the Def Con and Black Hat phishing campaign to see if further technical details regarding the malicious Google Doc Apps Script emerge. Coverage does not yet specify whether additional outlets will identify new victims or if platform providers like Google will take further action against the specific scripts utilized. Readers should consult ongoing updates from technical reporting organizations like Huntress and TechCrunch for the latest developments on the fake crypto conference threat.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Quick answers
Who was targeted by the phishing campaign?
Security researchers who attended the Def Con and Black Hat conferences.
What lure did the hackers use?
A fake crypto conference featuring the impersonation of a CoinDesk executive and a Google Doc.
Which organizations provided technical analysis of the malware delivery?
Huntress, TechCrunch, SC Media, Infosecurity Magazine, and Bitcoin World covered the campaign.
Coverage (5)
- Def Con Attendees Targeted by Persistent Phishing Campaign Infosecurity Magazine · 16h ago
- Fake Crypto Conference: Hackers Impersonate CoinDesk Executive To Target Researchers Bitcoin World · 16h ago
- Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure SC Media · 16h ago
- Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware Huntress · 16h ago
- Someone targeted security researchers using a fake crypto conference as a lure TechCrunch · 16h ago
Topics
Related trends
Fed probe of a16z cuts to core of venture capital
A Department of Justice investigation into Andreessen Horowitz's board seat practices is creating significant uncertainty across the venture capital industry.
Reddit’s AI is turning posts into podcasts and short videos
7 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Amazon, which started off selling books, is destroying rare texts to train AI
6 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
Investigators report an unprecedented number of Apple users have received alerts notifying them that they were targets of mercenary spyware.
Anthropic Revenue Run Rate Surpasses $65 Billion Ahead of IPO
Anthropic's annualized revenue run rate has reportedly surpassed $65 billion ahead of a widely anticipated public offering.
YouTube is changing how it counts views to give the numbers a boost
7 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.