During Black Hat and Def Con week, an attacker posed as a crypto news conference organizer and used a weaponized Google Doc to try installing malware on the people who hunt hackers.
In the days before Black Hat and Def Con, the two largest annual hacking conferences held back-to-back in Las Vegas, someone approached security researchers on X pretending to organize a crypto news conference. The lure was a planning document hosted on Google Docs, the kind of link a busy researcher might actually click.
According to Huntress's writeup, the document's sidebar had been customized with Google Apps Script to look like an encryption interface. The target was prompted to enter a "decryption key" supplied by the attacker. Doing so set off a chain tailored to the target's operating system: a macOS infostealer, a Windows remote-access tool repurposed as malware, or a fake installer for the Ledger hardware cryptocurrency wallet, depending on which OS the researcher ran.
The account Huntress fingered as the operator reached out in broken English and didn't reply to a direct message from TechCrunch. Google also didn't respond to a request for comment on whether it has seen weaponized Apps Script sidebars in Docs.
The portable check: a "decryption" prompt inside a Google Doc isn't a security feature. It's a phishing prompt that passes the first filter precisely because Google Docs is trusted.