Def Con DMs Lure Targets Into Fake Google Docs

Infosecurity Magazine · Medium sophistication
Last updated August 20, 2026

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

Key findings

  • Attacker initiated contact via X DMs after a security conference and impersonated a CoinDesk executive to request help with a fake upcoming conference.
  • First lure was a Google Doc with a custom Google Apps Script sidebar prompting for an “encryption key” and then offering ClickFix-style steps or a download to execute code.
  • Second lure was a fake Dropbox DocSend share leading to a counterfeit DocSend installer.
  • Payloads varied by OS (macOS infostealer; Windows crypto theft targeting Ledger wallets plus a proxy intended to evade checks).
  • When document/installer lures failed, the attacker pivoted to a new pretext offering funding “of up to $1m.”

Who’s being targeted

  • Commonly targeted roles: All employees attending conferences, Security/IT teams, Executives and senior staff active on social media, Finance/crypto holders (where relevant).
  • Affected industries: Cybersecurity / IT security, Media (impersonated brand), Conference attendees / professional networking targets.
  • Attack channels: linkedin, email.
  • Impersonated: CoinDesk VP and head of marketing, Dropbox DocSend (file-sharing invite).

Awareness takeaways

  • Treat post-conference outreach (DMs and “shared docs”) as high-risk and verify identities through a separate, trusted channel before opening files or links.
  • Be suspicious of any document workflow that asks for special keys/passwords or pushes you toward downloads or “fix steps” to make content work.
  • If a message asks you to bypass normal protections or run unusual actions, stop and report it, these are common compromise indicators.
  • If you interacted with a suspicious shared doc/installer, respond as if credentials may be exposed and take containment steps quickly.

Red flags to watch for

  • Unexpected DM from a stranger claiming a senior title and requesting help
  • Document requests an “encryption key” provided via DMs
  • Follow-on options include “instructions” and a “download” intended to execute code
  • Unexpected installer requirement to view a document share
  • Brand-name file share leading to software installation
  • Persistence: repeated follow-ups with new lures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You just got back from Def Con and a CoinDesk VP slides into your X DMs asking for help with a “new conference.” Sounds legit, right? Masquerading as CoinDesk’s VP, they send a Google Doc “planning document.” When you open it, a custom sidebar pops up asking for an encryption key from the DMs, then offers ClickFix-style steps or a download to run code. When that fails, they pivot: a Dropbox DocSend email shows up, pushing a 'DocSend installer' just to view a file. Same playbook: familiar brands, weird workflow, and pressure to download or run something. Here’s the move: after any conference, if a DM or email sends you to a shared doc that wants special keys, fix steps, or an installer, stop. Verify the person through a separate channel before you open or run anything.

Similar attacks

DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026
Fake LinkedIn Tests and Job Interviews Push Malware

Fake LinkedIn Tests and Job Interviews Push Malware

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS…

September 7, 2026