Def Con DMs Lure Targets Into Fake Google Docs

Infosecurity Magazine · Medium sophistication
Last updated August 20, 2026

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

Key findings

  • Attacker initiated contact via X DMs after a security conference and impersonated a CoinDesk executive to request help with a fake upcoming conference.
  • First lure was a Google Doc with a custom Google Apps Script sidebar prompting for an “encryption key” and then offering ClickFix-style steps or a download to execute code.
  • Second lure was a fake Dropbox DocSend share leading to a counterfeit DocSend installer.
  • Payloads varied by OS (macOS infostealer; Windows crypto theft targeting Ledger wallets plus a proxy intended to evade checks).
  • When document/installer lures failed, the attacker pivoted to a new pretext offering funding “of up to $1m.”

Who’s being targeted

  • Commonly targeted roles: All employees attending conferences, Security/IT teams, Executives and senior staff active on social media, Finance/crypto holders (where relevant).
  • Affected industries: Cybersecurity / IT security, Media (impersonated brand), Conference attendees / professional networking targets.
  • Attack channels: linkedin, email.
  • Impersonated: CoinDesk VP and head of marketing, Dropbox DocSend (file-sharing invite).

Awareness takeaways

  • Treat post-conference outreach (DMs and “shared docs”) as high-risk and verify identities through a separate, trusted channel before opening files or links.
  • Be suspicious of any document workflow that asks for special keys/passwords or pushes you toward downloads or “fix steps” to make content work.
  • If a message asks you to bypass normal protections or run unusual actions, stop and report it, these are common compromise indicators.
  • If you interacted with a suspicious shared doc/installer, respond as if credentials may be exposed and take containment steps quickly.

Red flags to watch for

  • Unexpected DM from a stranger claiming a senior title and requesting help
  • Document requests an “encryption key” provided via DMs
  • Follow-on options include “instructions” and a “download” intended to execute code
  • Unexpected installer requirement to view a document share
  • Brand-name file share leading to software installation
  • Persistence: repeated follow-ups with new lures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You just got back from Def Con and a CoinDesk VP slides into your X DMs asking for help with a “new conference.” Sounds legit, right? Masquerading as CoinDesk’s VP, they send a Google Doc “planning document.” When you open it, a custom sidebar pops up asking for an encryption key from the DMs, then offers ClickFix-style steps or a download to run code. When that fails, they pivot: a Dropbox DocSend email shows up, pushing a 'DocSend installer' just to view a file. Same playbook: familiar brands, weird workflow, and pressure to download or run something. Here’s the move: after any conference, if a DM or email sends you to a shared doc that wants special keys, fix steps, or an installer, stop. Verify the person through a separate channel before you open or run anything.

Similar attacks

DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
Fake Downloads and Extensions Steal Sessions Fast

Fake Downloads and Extensions Steal Sessions Fast

The article highlights real, ongoing campaigns where attackers trick people into installing malware via fake software-download websites and a disguised browser extension. These lures are used to steal credentials, browser cookies, and authenticated sessions, letting attackers take over accounts…

September 11, 2026
Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026