The threat actor initiated contact via X, engaging targets with inquiries about conference attendance. By leveraging a legitimate Google Doc integrated with Google App Script, the attacker crafted a deceptive interface designed to bypass suspicion. Victims were prompted to enter a bogus decryption key, which triggered the deployment of an infostealer for Apple devices, a repurposed remote desktop tool for Windows, and a counterfeit Ledger cryptocurrency wallet installer.
Huntress researchers uncovered the scheme after one of their own was targeted. The security firm observed that the attacker successfully mimicked professional correspondence despite utilizing broken English. While state-sponsored groups frequently target security professionals, this specific operation relied on the abuse of trusted Google infrastructure to lend an air of legitimacy to the malicious payload. The account behind the campaign remained unresponsive to requests for comment, and Google has yet to address whether this vector is being utilized in broader attacks.

Comments (0)
No comments yet. Be the first!