Cybercriminals targeted Black Hat/DEF CON attendees with convincing post-conference outreach that ultimately delivered information-stealing malware and remote access tools, according to a recent report by SC Media. Huntress uncovered the campaign after a researcher was contacted by an attacker impersonating a CoinDesk executive who shared a malicious Google Doc disguised as a conference planning document.
Opening the document while signed into Google could trigger reconnaissance that collected information including the victim’s IP address, operating system and installed cryptocurrency wallets. Attackers then used fake decryption errors and ClickFix-style instructions to push Windows and macOS malware, including payloads consistent with Atomic macOS Stealer and NetSupport RAT.
Huntress also observed a second lure using a fake Dropbox DocSend site. The campaign highlighted the risks of trusted cloud platforms being weaponized for social engineering and reinforced the need to scrutinize post-event outreach, especially requests to run terminal commands, install software or bypass security controls.
For MSPs, the Black Hat/DEF CON malware campaign is a reminder that social engineering increasingly extends beyond email and into trusted collaboration platforms such as Google Docs. MSPs should ensure clients have controls and training that address these newer attack paths, particularly requests to run terminal commands, install software or bypass built-in security protections.
Source: SC World












