Be careful who you talk to at conferences: Security researchers claim they were targeted by cyber criminals after DEF CON event

Scammers contacted conference attendees with a booby-trapped Google Doc designed to look like a routine post-event contact

Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop.
(Image credit: Getty Images)

Visitors to Black Hat/DEF CON earlier this month were targeted after the event by cyber criminals posing as a well-known crypto media executive.

The X account @HartmansDoeke sent a direct message to one Huntress security researcher claiming to be CoinDesk's VP and head of marketing, asking for help with an upcoming conference.

While the researcher cottoned on to the scam immediately, they carried on engaging with the scammer to check out the tactics they were using. This involved a Google Doc featuring a custom Google Apps Script sidebar designed to guide them through the execution of malware.

The document asked the potential victim to enter an 'encryption key' – supplied by the actor in direct messages – which appeared to fail when entered. The sidebar provided two follow-on options: ClickFix-style instructions and a download option, both intended to download and execute malicious code.

Latest Videos FromIT Pro

Mac users were served an infostealer targeting browser passwords, crypto wallets and even private Notes app data. Meanwhile, Windows users were served a remote access trojan, a fake crypto wallet implant, and a network-intercepting proxy delivered via an installer signed with what appears to be a stolen certificate.

When the researcher didn't fall for the malicious Google Doc, the threat actor followed up the next day with a second malicious document.

This masqueraded as a Dropbox DocSend share and led to a counterfeit DocSend installer that delivered AMOS stealer to macOS users and NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy to those on Windows.

"Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged," Huntress said. "By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the malware."

Conference attendees urged to remain vigilant

According to Huntress, the researcher was just one of many to be targeted.

"Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans," Huntress said.

"Attackers are using this activity to make malicious outreach look like just another routine post-conference interaction."

Anybody who's interacted with a lure like this is advised to isolate the system from the network, collect any relevant forensic evidence, and consider reimaging the system.

They should assume that credentials on the system have been compromised and revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system – and also review any cryptocurrency wallets.

While visitors to a security conference might not seem like the most obvious victims, this wasn't the only attempt to scam this year's DEF CON attendees.

One passenger on a Delta flight out of Las Vegas attempted to jam in-flight Wi-Fi and broadcast a rogue network designed to look like the airline’s service, in an apparent phishing attempt.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.