DEF CON Attendees Hit With Fake CoinDesk DMs

IT Pro Security · High sophistication
Last updated August 21, 2026

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

How the attack worked

After Black Hat and DEF CON, an X account impersonating CoinDesk's VP and head of marketing sent direct messages to conference attendees, opening with a request for help on an upcoming conference. This framing made the outreach feel like a routine networking follow-up rather than a cold approach from a stranger.

The first lure was a Google Doc containing a custom Google Apps Script sidebar. The document asked the target to enter an 'encryption key' supplied by the attacker in the DMs, then presented options that led to downloading and executing malicious code. When a researcher did not engage with this document, the attacker followed up the next day with a second lure disguised as a Dropbox DocSend share, which led to a counterfeit DocSend installer.

The payloads differed by operating system. macOS targets received AMOS stealer style malware, while Windows targets received NetSupport RAT along with a Ledger wallet implant and a traffic-intercepting proxy.

Why it succeeded

Huntress assessed that the approach worked by building credibility through familiar platforms. Google Docs and Dropbox DocSend are tools many professionals use daily, and a multi-step workflow that mimics normal document sharing keeps a target engaged longer than a single suspicious link would. Large industry events like Black Hat and DEF CON create a target-rich environment, since attendees expect new contacts and follow-up messages after networking.

What to watch for

  • Unexpected direct messages from a supposed executive shortly after a conference, especially requesting help with a task
  • A document that requires entering an 'encryption key' provided by the sender before it will display content
  • Sidebars, helpers, or prompts inside a document that push you toward downloading or running software
  • A second follow-up document or link the day after you ignore the first one
  • Installers tied to file-sharing brands like DocSend that arrive unexpectedly

Building resistance

Treat any new post-event contact as unverified until confirmed through a separate, known channel, such as a company directory or an existing colleague. Be cautious of any document that tries to walk you through entering codes or running installers. If you have interacted with a lure like this, assume credentials on the system may be compromised: isolate the device from the network, revoke active sessions, reset passwords, and rotate API keys. Building awareness of these multi-step, platform-mimicking workflows helps employees pause before completing the full chain an attacker is counting on.

Key findings

  • Attackers used an X account to impersonate “CoinDesk's VP and head of marketing” and start a post-conference conversation.
  • The first lure used a Google Doc with a “custom Google Apps Script sidebar” that prompted the target to enter an “encryption key,” then offered options intended to download/execute malicious code.
  • The second lure mimicked a “Dropbox DocSend share” leading to a counterfeit installer.
  • Payloads differed by OS: macOS victims were served AMOS/infostealer-style malware; Windows victims were served NetSupport RAT plus crypto wallet implants and a traffic-intercepting proxy.
  • Huntress assessed the approach as credibility-building: familiar platforms + a legitimate-looking, multi-step workflow to keep targets engaged.

Who’s being targeted

  • Commonly targeted roles: All employees attending conferences/events, Security/IT teams, Executives and senior leaders, Finance/Crypto asset holders, Marketing/BD (frequent external outreach).
  • Affected industries: Cybersecurity / security research, Technology conference attendees, Cryptocurrency users, Airlines (related phishing attempt mentioned).
  • Attack channels: website.
  • Impersonated: CoinDesk VP and head of marketing, Dropbox DocSend (masqueraded share).

Red flags to watch for

  • Unexpected social media DM from a ‘well-known’ executive after a conference
  • Document requires an ‘encryption key’ from a stranger and then pushes software/code execution
  • Follow-up pressure via additional ‘documents’ when the first attempt fails
  • Unexpected “DocSend” installer requirement to view a document
  • Installer/source is counterfeit despite using a trusted brand
  • Second-day follow-up after non-engagement (persistence)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attackers first contact victims?

An X account impersonating CoinDesk's VP and head of marketing sent direct messages to conference attendees asking for help with an upcoming conference.

What made the Google Doc lure convincing?

It used a custom Google Apps Script sidebar that walked the target through entering an 'encryption key' supplied by the attacker, then guided them toward executing malicious code.

What happened if the target didn't fall for the first lure?

The threat actor followed up the next day with a second lure disguised as a Dropbox DocSend share that led to a counterfeit installer.

What malware was delivered to victims?

macOS users were served AMOS stealer-style malware, while Windows users received NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy.

Read the video transcript

You just got back from DEF CON, and an X DM pops up: “Hey, I’m CoinDesk’s VP of marketing, can you help with our next conference?” They send a Google Doc. On the right, a custom sidebar pops up: it asks for an 'encryption key' from the DM, then walks you to download and run a file to 'decrypt' it. If you hesitate, they follow up with a fake Dropbox DocSend share that insists you install a 'DocSend viewer', on macOS that drops AMOS infostealer, on Windows NetSupport RAT and crypto wallet implants. Here’s the move: any post-conference DM that sends you a doc and then a helper app? Stop. Don’t install anything, report it to security and verify the person through a known-good channel.

Similar attacks

Def Con DMs Lure Targets Into Fake Google Docs

Def Con DMs Lure Targets Into Fake Google Docs

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

August 20, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Fake CAPTCHA “Copy/Paste” Sites Push CastleLoader

Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”). The article describes real campaigns tied to CastleLoader and similar activity, including fake background-removal sites and job-site…

July 23, 2026
Fake CAPTCHA Tricks Ukrainians Into Running Malware

Fake CAPTCHA Tricks Ukrainians Into Running Malware

CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell commands that infect their own computers. The campaign also includes Android attacks where victims are sent trojan APK “security tools” via…

July 19, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026