A phishing campaign has targeted attendees of the Black Hat and Def Con cybersecurity conferences in Las Vegas. Attackers used social engineering, impersonating an executive from the media outlet CoinDesk to deceive their targets.
Anatomy of the Scam
According to the cybersecurity platform Huntress, the attack began on X. An attacker, using a fake account purportedly belonging to CoinDesk's VP and Head of Marketing, sent direct messages to individuals who had attended the recent hacker conferences. The lure involved an invitation to a non-existent online cryptocurrency conference.
To build credibility, the attackers used links from services such as Google Docs and Dropbox DocSend. When a victim opened the document, they were prompted to enter an encryption key. This process was a ruse, designed to lead the user to download malware through alternative options presented on the screen.
Targets and Malware Payloads
The attack was engineered to compromise various operating systems and digital assets:
- macOS: Installation of information-stealing software.
- Windows: Installation of a remote access tool.
- Crypto Wallets: Distribution of a fake installer for the Ledger wallet.
The scam was uncovered when a Huntress researcher recognized the bait and engaged with the attacker to analyze their tactics. While no victims have been reported publicly and the fake X account has been deleted, the case highlights how cybercriminals exploit trust in established file-sharing platforms to convince targets to execute malware.