Def Con DMs Lure Targets Into Fake Google Docs

Infosecurity Magazine · Medium sophistication
Last updated August 20, 2026

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

Key findings

  • Attacker initiated contact via X DMs after a security conference and impersonated a CoinDesk executive to request help with a fake upcoming conference.
  • First lure was a Google Doc with a custom Google Apps Script sidebar prompting for an “encryption key” and then offering ClickFix-style steps or a download to execute code.
  • Second lure was a fake Dropbox DocSend share leading to a counterfeit DocSend installer.
  • Payloads varied by OS (macOS infostealer; Windows crypto theft targeting Ledger wallets plus a proxy intended to evade checks).
  • When document/installer lures failed, the attacker pivoted to a new pretext offering funding “of up to $1m.”

Who’s being targeted

  • Commonly targeted roles: All employees attending conferences, Security/IT teams, Executives and senior staff active on social media, Finance/crypto holders (where relevant).
  • Affected industries: Cybersecurity / IT security, Media (impersonated brand), Conference attendees / professional networking targets.
  • Attack channels: linkedin, email.
  • Impersonated: CoinDesk VP and head of marketing, Dropbox DocSend (file-sharing invite).

Awareness takeaways

  • Treat post-conference outreach (DMs and “shared docs”) as high-risk and verify identities through a separate, trusted channel before opening files or links.
  • Be suspicious of any document workflow that asks for special keys/passwords or pushes you toward downloads or “fix steps” to make content work.
  • If a message asks you to bypass normal protections or run unusual actions, stop and report it, these are common compromise indicators.
  • If you interacted with a suspicious shared doc/installer, respond as if credentials may be exposed and take containment steps quickly.

Red flags to watch for

  • Unexpected DM from a stranger claiming a senior title and requesting help
  • Document requests an “encryption key” provided via DMs
  • Follow-on options include “instructions” and a “download” intended to execute code
  • Unexpected installer requirement to view a document share
  • Brand-name file share leading to software installation
  • Persistence: repeated follow-ups with new lures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You just got back from Def Con and a CoinDesk VP slides into your X DMs asking for help with a “new conference.” Sounds legit, right? Masquerading as CoinDesk’s VP, they send a Google Doc “planning document.” When you open it, a custom sidebar pops up asking for an encryption key from the DMs, then offers ClickFix-style steps or a download to run code. When that fails, they pivot: a Dropbox DocSend email shows up, pushing a 'DocSend installer' just to view a file. Same playbook: familiar brands, weird workflow, and pressure to download or run something. Here’s the move: after any conference, if a DM or email sends you to a shared doc that wants special keys, fix steps, or an installer, stop. Verify the person through a separate channel before you open or run anything.

Similar attacks

DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026
AI Chatbots Outperform Humans in Romance Scams

AI Chatbots Outperform Humans in Romance Scams

Researchers simulated “pig butchering” romance-style scams and found an AI chatbot built trust more effectively than a human scammer over a week of texting. In the test, victims were significantly more likely to comply with the AI’s request to install an app, showing how AI could automate the long…

July 30, 2026
Fake CAPTCHA Tricks Ukrainians Into Running Malware

Fake CAPTCHA Tricks Ukrainians Into Running Malware

CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell commands that infect their own computers. The campaign also includes Android attacks where victims are sent trojan APK “security tools” via…

July 19, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026