Def Con Attendees Targeted by Sophisticated Post-Conference Phishing Campaign
Cybersecurity professionals attending Def Con and Black Hat were targeted by a persistent, multi-stage phishing campaign employing social engineering and custom malware.

Attendees of major cybersecurity conferences, including the recent Black Hat and Def Con events, are being warned to remain vigilant against sophisticated phishing attempts that can emerge long after the conferences conclude. A detailed analysis by security vendor Huntress reveals a persistent threat actor who meticulously crafted a social engineering scheme to compromise victims, leveraging familiar platforms to build trust and deliver malicious payloads.
The campaign began with the threat actor impersonating a CoinDesk executive on X (formerly Twitter), reaching out to a Huntress researcher under the guise of needing assistance with a fictitious upcoming conference. While the researcher recognized the scam, they engaged to better understand the attacker's methods. The actor then sent a Google Doc, which appeared to be a planning document for the supposed event. However, this document contained a custom Google Apps Script sidebar designed to execute malicious code.
If an authenticated Google user opened the document, the sidebar would prompt them to enter an "encryption key." Upon failure to do so, two options were presented: "ClickFix-style instructions" or a "download option." Both were designed to trick the user into downloading and executing malware. This approach demonstrated a move beyond simple credential harvesting, aiming for direct system compromise.
Undeterred by the initial lack of success, the threat actor followed up the next day with a second lure. This time, the attacker presented a fake Dropbox DocSend share link, leading to a counterfeit DocSend installer. The payload delivered by this installer varied based on the victim's operating system. For macOS users, the malware was an infostealer known as AMOS. For Windows users, the payload was an implant specifically designed to steal cryptocurrency from Ledger wallets, alongside a proxy designed to evade security software and detection mechanisms like VirusTotal.
The dual-lure strategy highlights the attacker's adaptability and understanding of common workflows. By combining social media direct messages with trusted document and file-sharing services, the actor created a seemingly legitimate process intended to bypass user caution and trick targets into running malicious code. Even after these attempts, the actor reportedly pivoted again, inquiring if the researcher knew anyone seeking significant funding, a potential pretext for further credential or personally identifiable information (PII) theft.
Huntress advises conference attendees to be wary of any seemingly legitimate messages that request unusual actions, such as running terminal commands, bypassing security features like Gatekeeper, or installing manual updates. These are strong indicators of a potential compromise attempt rather than routine technical support.
In the event of interaction with such a malicious message, Huntress recommends immediate system isolation from the network. Users should collect forensic evidence, consider reimaging the affected system, and assume that any credentials used on the compromised machine have been compromised. This includes revoking active sessions, resetting passwords, and rotating API keys or other secrets. For users dealing with cryptocurrency, reviewing wallet activity is also crucial.
This campaign underscores the evolving tactics of threat actors who leverage social engineering and familiar platforms to conduct sophisticated attacks. The targeting of cybersecurity professionals themselves, particularly following events where such individuals are likely to be more engaged and potentially less cautious due to conference-related interactions, represents a significant escalation in attacker strategy.