ImportantSecurity & Privacy
Someone targeted security researchers using a fake crypto conference as a lure
Threat actors are conducting sophisticated social engineering campaigns targeting cybersecurity professionals using fake crypto conference lures and weaponized Google Docs with custom sidebars to distribute macOS and Windows malware. This attack demonstrates that adversaries are increasingly leveraging legitimate third-party tools and platforms (Google Apps Script) to bypass traditional security defenses, creating a new attack vector that exploits trust in mainstream productivity tools. IT organizations must enhance employee security awareness training, implement stricter controls around Google Docs sharing policies, and establish verification protocols for conference invitations to prevent similar supply-chain-adjacent compromises.
