Around Black Hat and DEF CON in August 2026, an attacker posing as CoinDesk’s vice president and head of marketing contacted cybersecurity professionals on X and used a fake conference invitation to deliver a maliciou... The deception worked because the document was hosted on genuine Google infrastructure: a custom...
Research answer

Create a landscape editorial hero image for this Studio Global article: How did a hacker posing as an employee of a leading crypto news site target cybersecurity professionals on X around the Black Hat and Def Co. Article summary: A threat actor posing on X as CoinDesk’s VP and head of marketing used a fake crypto-conference invitation to target Black Hat and Def Con attendees, aiming to make them install malware on macOS or Windows. The public re. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
The campaign combined a familiar professional setting with trusted online services. An account on X, @HartmansDoeke, claimed to represent CoinDesk and approached people associated with Black Hat and DEF CON, sometimes through public replies before moving the conversation into direct messages. The attacker then proposed a supposedly CoinDesk-organized cryptocurrency conference and shared a Google Doc presented as planning material. 1411
The important distinction is that the Google document itself could look legitimate. The malicious behavior came from an embedded Google Apps Script interface and the instructions delivered through it. The supplied reporting describes an attempted malware delivery chain; it does not establish that the Huntress researcher or other targets installed the payload. 468
The opening messages used the conference context as a credibility shortcut. The impersonator asked, in broken English, whether the researcher planned to attend another event and then introduced a fictitious conference connected to a well-known crypto news outlet. Public replies helped identify or approach likely attendees, while DMs created a private channel for the next steps. 4510
Once the target showed interest, the actor sent a document that appeared to be a conference-planning file. The document was paired with an “encryption” or decryption key supplied in the X conversation. This made the exchange feel like ordinary event coordination rather than a conventional phishing attempt. 68
An authenticated Google user opening the file saw a custom sidebar alongside the document. Huntress described the sidebar as an interface that made the material appear partially encrypted and prompted the recipient to enter the supplied key. The key appeared to fail, creating a reason for the target to follow the sidebar’s suggested recovery steps. 68
Those follow-on options included ClickFix-style instructions and a download path. Both were intended to persuade the recipient to download and execute malicious code. In other words, the document was not merely a link to a suspicious external page: legitimate Google hosting and a native-looking Docs interface were used to make the workflow feel familiar. 48
That trust signal is the campaign’s central lesson. A real google.com URL or a document that opens inside a known productivity service can confirm where content is hosted, but it does not prove that the document, script, instructions, or downloads are safe.
The reported delivery paths differed by operating system:
The available evidence describes intended payloads and delivery mechanisms, not a confirmed compromise of the researcher who investigated the campaign.
The targeted Huntress researcher recognized the approach as suspicious but continued the conversation while pretending to cooperate. That allowed Huntress to observe the actor’s messages, receive the document, and document how the fake encryption prompt led toward malware execution. The researcher did not install the payload. 1411
This method produced unusually useful visibility into the attack chain. Instead of stopping at the first suspicious message, the investigation connected the X identity claim, the conference pretext, the Google Doc, the Apps Script sidebar, the fake key prompt, and the operating-system-specific malware paths.
The campaign shows why conference-related outreach deserves the same scrutiny as email phishing, even when it arrives through a public social platform and uses a legitimate cloud service.
Practical warning signs include:
If someone followed the instructions, the safest response is to isolate the affected system, reset potentially exposed credentials, rotate secrets, and review cryptocurrency wallets and other sensitive accounts. 1819
The reporting supports the core mechanics: impersonation on X, public replies and DMs, a fake crypto-conference pretext, a Google Doc enhanced with Apps Script, a supplied fake decryption key, ClickFix-style follow-on instructions, and attempted delivery of malware affecting macOS and Windows. 1246811
The supplied record does not provide a verified statement from the suspected attacker or Google. It also does not contain enough evidence for a specific comparison with named government-linked campaigns. At a broad level, the incident fits a familiar pattern of tailored social engineering against security professionals, while its notable variation is the use of trusted Google-hosted content and an Apps Script interface as part of the delivery flow.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Around Black Hat and DEF CON in August 2026, an attacker posing as CoinDesk’s vice president and head of marketing contacted cybersecurity professionals on X and used a fake conference invitation to deliver a maliciou...
Around Black Hat and DEF CON in August 2026, an attacker posing as CoinDesk’s vice president and head of marketing contacted cybersecurity professionals on X and used a fake conference invitation to deliver a maliciou... The deception worked because the document was hosted on genuine Google infrastructure: a custom Google Apps Script sidebar made it look encrypted, asked for a key supplied by DM, and then presented ClickFix style step...
A Huntress researcher recognized the scam and pretended to cooperate, documenting the attack chain without installing the payload.