HomeCyber BalkansFake Crypto Executive Used Booby-Trapped Google Doc to Attack Security Researcher After...

Fake Crypto Executive Used Booby-Trapped Google Doc to Attack Security Researcher After DEF CON

Published on

spot_img

A recent investigation by Huntress has unveiled a sophisticated phishing attack orchestrated by a threat actor impersonating a high-ranking executive at a prominent cryptocurrency media outlet. This deceitful campaign targeted a security researcher in the wake of the Black Hat and DEF CON conferences held earlier this year. The research highlights the evolving tactics employed by cybercriminals, which now encompass stages that utilize commonly trusted platforms to enhance their credibility.

The phishing campaign commenced on August 9, when the impersonating account contacted the researcher through X, the platform formerly known as Twitter. The attacker crafted a narrative about organizing an online conference to engage the researcher and initiated a conversation. Notably, the account had a unique profile, merging the photograph of one individual with the name of another, illustrating the extent to which the actor was willing to deceive. This fraudulent outreach was not limited to a single individual; it also targeted a variety of attendees from the aforementioned conferences, utilizing a boilerplate message.

Instead of severing communication upon realizing the deceit, the researcher made a strategic decision to engage further. This approach was aimed at understanding the attacker’s methods, allowing Huntress to meticulously document the entire process from the initial communication to the delivery of malicious software.

The lure employed in this phishing scheme proved to be more intricate than a standard phishing link. The attacker presented what was purported to be a planning document for the fictitious conference, hosted on Google Docs. When accessed with an authenticated Google account, this document activated a custom sidebar developed using Google Apps Script, intriguingly named “DecryptPanel.html.” This sidebar prompted the recipient to input an “encryption key” that had been conveyed earlier in the exchange.

Upon submission of the key, the victim received a fabricated “failure” message, with the sidebar subsequently urging them to proceed with the “Document Decryption” instructions. These instructions provided two options: executing a ClickFix command manually or downloading a “Manual Update.” Researchers discovered that the underlying script had a dual purpose—it not only validated a narrow set of pre-defined keys but also gathered critical information about the victim’s device. Additionally, it sent activity updates to the actor via Telegram and dynamically diverted targets down different malware paths depending on their operating system.

For macOS users, the process involved executing a terminal command that, during Huntress’s testing, pointed to an infrastructure trapped in a redirect loop, indicating possible incompleteness of the intended payload. Alternatively, users could pursue a “Manual Update” that directed them to a GitHub Releases page. This page presented a disk image that attempted to circumvent Apple’s Gatekeeper protections to initiate installation. Further analysis revealed strong resemblances to the Atomic macOS Stealer (AMOS), a malicious tool designed to extract browser credentials, cryptocurrency wallet information, keychain data, and Telegram files. The malware also aimed to establish persistence through a scheduled background process.

On the other hand, Windows users who followed the decryption path were prompted to install a fraudulent “Google API Connector” update. Huntress identified this as a ClickOnce application signed with a certificate likely misappropriated from a Norwegian firm. Once the application was installed, it replicated a legitimate Google Workspace Marketplace interface while stealthily downloading additional payloads, including NetSupport Remote Access Trojan (RAT), a counterfeit Ledger cryptocurrency wallet application, and tools for intercepting network traffic.

The persistence of the threat actor was evident in their subsequent attempt, made the day after the initial interaction failed. The researcher received a second malicious document masquerading as a Dropbox DocSend file. This document functioned to deliver the AMOS stealer to macOS users or the same Windows malware previously discussed.

Huntress emphasized the relevance of this campaign as a reflection of the changing landscape of cybersecurity threats. Attackers are increasingly crafting multi-stage workflows that leverage trusted social media, cloud document platforms, and code-hosting sites to establish a credible narrative, rather than relying solely on a single dubious link.

This incident arrives amidst broader concerns about phishing attacks targeting participants of major security conferences, with numerous reports surfacing on social media that highlight similar tactics employed in the aftermath of this year’s Black Hat and DEF CON events in Las Vegas.

To further aid awareness and understanding, Huntress has disclosed a comprehensive technical breakdown of this campaign, including pertinent indicators of compromise, on its official blog. The ongoing efforts by security researchers to document such attacks play a crucial role in safeguarding individuals and organizations against increasingly sophisticated phishing schemes in the digital landscape.

Source link

Latest articles

EHR Vendor Alerts 3.8 Million Patients About Data Theft Hack

CareCloud Reports Major Data Breach Affecting Nearly 3.8 Million Patients In a significant data breach...

OpenAI Temporarily Slows Scaling Efforts and Ensures Zero Data Retention for Select Frontier Model Customers

OpenAI's Recent Developments Under Scrutiny by Industry Experts In recent developments regarding OpenAI, industry experts...

Raspberry Pi Introduces CM5 Batch Provisioning Jig

Raspberry Pi has unveiled its latest offering: a dedicated Programming Jig, priced at $600,...

OpenAI Halts Frontier Model Training for Safety Evaluation

OpenAI's Voluntary Training Pause Highlights Accountability Gaps in AI Development In a notable move concerning...

More like this

EHR Vendor Alerts 3.8 Million Patients About Data Theft Hack

CareCloud Reports Major Data Breach Affecting Nearly 3.8 Million Patients In a significant data breach...

OpenAI Temporarily Slows Scaling Efforts and Ensures Zero Data Retention for Select Frontier Model Customers

OpenAI's Recent Developments Under Scrutiny by Industry Experts In recent developments regarding OpenAI, industry experts...

Raspberry Pi Introduces CM5 Batch Provisioning Jig

Raspberry Pi has unveiled its latest offering: a dedicated Programming Jig, priced at $600,...