# Someone targeted security researchers using a fake crypto conference as a lure

> **Open Intelligence Dossier** · First detected: 2026-08-21 10:07 UTC · Category: Technology

## Executive Summary
Security experts and conference attendees face a targeted phishing campaign involving a fake crypto event and booby-trapped documents.

## Intelligence Brief
Recent reports from outlets including TechRadar, TechCrunch, Infosecurity Magazine, and SC Media reveal an ongoing security threat directed at professionals within the cybersecurity industry. Specifically, attendees of major industry gatherings such as Black Hat and DEF CON have been targeted by malicious actors utilizing sophisticated social engineering tactics. According to the coverage, the scheme involves a fabricated cryptocurrency conference and the impersonation of a CoinDesk executive to deceive victims. Coverage does not yet specify the total number of individuals compromised or the exact identities of the perpetrators behind the operation. Additional technical breakdowns provided by Huntress and itsecurityguru.org detail the exact mechanisms employed in the attacks.


The campaign relies heavily on a booby-trapped Google Doc containing malicious Apps Script designed to deliver malware and prompt users into handing over sensitive details. This lure was deployed directly against researchers following the conclusion of the DEF CON conference. While sources such as Zamin.uz and Bitcoin World confirm the broad outlines of the fake crypto conference scam, specific details regarding the broader infrastructure of the threat group remain under investigation by reporting organizations. This malicious activity fits into a broader pattern of persistent post-conference phishing campaigns that exploit the professional interests and networking habits of security researchers. By leveraging familiar industry touchpoints like high-profile crypto media brands and major hacker conventions, the attackers aim to bypass the natural skepticism of technical experts.


Coverage emphasizes that targeting cybersecurity professionals immediately after major conventions represents a calculated approach by the threat actors, capitalizing on the high volume of post-event communications and follow-up networking requests. As the investigation into the post-DEF CON phishing campaign continues, observers and participants are tracking further updates from technical analysts and security news outlets. Coverage does not yet specify whether law enforcement agencies have intervened or if additional conference dates outside of the Black Hat and DEF CON cycle have been targeted by the same malicious network. Future updates from reporting organizations are expected to provide more insight into the specific strains of malware delivered through the Google Doc Apps Script mechanism and any broader implications for the affected technical community.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| TechRadar | Security experts targeted by fake crypto conference in scam to hand over details | [Source Link](https://news.google.com/rss/articles/CBMiuwFBVV95cUxQbXlIUElsdE5Uc0pENlA4TVRyRnBNaVJxUGNBTU9ycU0yY2Z6cWp5UExSUUVQUzF3M2NFcjh0RUFsMUROalFCYzVlY2tibUpFQW14cFNSVWZYNnlLa2tkbGhyR2VvR01fMFVWc3hCTHBqY0UzTldkal9VWkkxX0FFdVJDOGNyVXZfRXY5VVloOUpDcXp1X3NlTUgyUExhTTFBazY4dWN3VHdzelNjX2xnZlFPcWJxbVZPNm9n?oc=5) |
| itsecurityguru.org | Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON | [Source Link](https://news.google.com/rss/articles/CBMizgFBVV95cUxPaTVTU2lQSUNMREc5Sml1Sk9JbXdseW81NURpZ3RtWGVyOC1kTm12dGd5LS13ZTFHbm0zeGxFOTIxc1VzajR3YVhFenRnWHQ3VVN1ZzY3QUtOdUFIalY0U1hfOXRWODhnR3FmYjNaNFl4TVpGczZSQjRmUkN5YzFTUTItcXhWbk5YQldfeFhTcWk5bnJ0WFhBSjUyRGZBak5zaXZjakFOV2VYVmpSbU9ueU1EYkxXS1Jnd3ZlS2FHaEZUNmFnWjlwOF83Mkc3UQ?oc=5) |
| Zamin.uz | Cybersecurity Experts Targeted in Fake Conference Scam | [Source Link](https://news.google.com/rss/articles/CBMingFBVV95cUxNSzZoYUU3YzI2OFhjRkl0Q1NqT1ZoNjB5b3dfcS1UOEFyOUkxcUFSS1lTd2ozOWg0Q0NKbXpvd2pLSkU3QkplMjZNTTZXTUgyY0g5eTNkQVVrOTVfTGJBUjM3Q2VKQ2szSnRuNHFsdmdpemk3LW9Na1U4cDJraXduYW9tenZTTUFUcGxqejhjUl9HaDcyLWtjR1hPZEVmdw?oc=5) |
| Infosecurity Magazine | Def Con Attendees Targeted by Persistent Phishing Campaign | [Source Link](https://news.google.com/rss/articles/CBMifEFVX3lxTE9OVHNsRDdZSXdDRVVzWlVvZ3dCcG5lc1RlRVdyazBjTURRdUM2NFdZM2FPSENUVHN5VmpjVWxqMDBKQVdHWHhveHlIZHhGNElJMWZWN0RJR2R0T0pob2wzRG50X1B6b1lvYVB3SVZrUGhoR3FUWXljaDFqZDk?oc=5) |
| Bitcoin World | Fake Crypto Conference: Hackers Impersonate CoinDesk Executive To Target Researchers | [Source Link](https://news.google.com/rss/articles/CBMifkFVX3lxTE9MQUdKUzBLbEpaYlpoNmRDS1FVeGRzQWFYUnhnRTVqU0RaVS1nNzJzNTJfTVppeTVrbW5MZDl3aVRJTmNwVmJsLTlwSVVYeEIwMDhZSXBqMDJCVng2XzN4S2JMWjRLdUVGNUUwWHRWalQzaWRpSy0xSXVmVU83UQ?oc=5) |
| SC Media | Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure | [Source Link](https://news.google.com/rss/articles/CBMipwFBVV95cUxOUDRiVWE0WWhubU5hc3U4dXl1RkdHRUY5X2pCTkdrTFpWREdkQTZaelVVa2NjSjg5bEpmN1djbGNKX2puQ0hzSmJicU56N3llQXJIVHhFS3VZZzh4a0gtOUxwM1lWeDAxWERJMDJBbnRNX2U4OVRDdlpoMDk1MVpJWDkwemRiTkRfQVBFN2UxWmxmMXZlZVFkeHBSM3JyUEE0eDdoV2M2Yw?oc=5) |
| Huntress | Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware | [Source Link](https://news.google.com/rss/articles/CBMickFVX3lxTE1KWHBBaVlCdXllVjZyMXlMNlJMN0dVRDV0c1J3UVR4aHlYdWdXQURHOHJEamNlRmZQMllOekk4dlV1ZEVrVUoxc09TMnljZjNONHdQLTNBZWpqZDc3alhUTkgtNVhsdEtvQ2RoZjRXamRQQQ?oc=5) |
| TechCrunch | Someone targeted security researchers using a fake crypto conference as a lure | [Source Link](https://news.google.com/rss/articles/CBMiswFBVV95cUxNeW5xb3ZJWEhURDBDRUJOdkd4UDYwbzdkRktfajQ0dW5iTzctYUlDSVJwd2FxMGU2ZHZBdDRadWNocUhPdTJiZF8wSGczRXU5REdyOUZia3g5QnJlaWFRX2NhRkNMU25IZWJHTnlFaWw4M290OU5MeHhSLVdpUWY3cUN0Y2hZRTBmdEFxaFktX3Y5bEttbTJMLWJMcXRPcW9VdDBNSkt3TjNyZjVYcWFoYVFfaw?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-08-21/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure*
