The security company Huntress disclosed that in early August, before and after the Black Hat and Def Con meetings, the assailants impersonated a well-known encrypted media worker, contacted a number of cybersecurity researchers on X and induced the target to follow up on the grounds that there was no encrypted meeting.

Using Google Docs to disguise meetings

According to the Huntress announcement process, the attackers first contact their targets through public responses and private correspondence, asking if they were planning to participate in the next meeting and then throw out the information about the so-called activities sponsored by encrypted media. This was not followed by a clearly malicious link, but by a real Google Docs document, which appeared to be a meeting preparation material.

This document contains a designed sidebar intended to allow visitors to misperceive the content as encrypted. The attackers then provided so-called “declassified keys” to induce target input. Huntress believes that this step is the entry point for subsequent malicious proceedings.

MacOS, Windows are in range. Internal

Huntress states that the attack chain boosts different loads according to the system used by the target:

  • For Apple's computer, it's an information steal program.
  • A modified remote desktop viewer for Windows
  • There is also a false installation package disguised as the Ledger Wallet Installer

After identifying the anomalies, a Huntress researcher continued to interact with each other in order to observe their complete modus operandi and to collate the details of the attack accordingly.

Use real tools to improve confusion

Such targeted attacks against security practitioners are not uncommon. In the past, it was mentioned that security researchers had been targeted, both by hackers from national backgrounds and by attacks using false social accounts.

The more confusing part of the incident was that the attackers did not send crude malicious documents directly, but instead borrowed the real Google Docs and associated interface elements to lower the target ' s vigilance. TechCrunch states that it contacted the relevant account number marked by Huntress by a private letter via X but did not respond. Google also did not immediately respond to media queries about whether similar events were noted.