DEF CON Phishing Campaigns Deliver Malware via Google Docs and Social Media
Following DEF CON, there have been reports of phishing campaigns targeting attendees. One such campaign involved an attacker posing as CoinDesk's VP and Head of Marketing on the X account @HartmansDoeke, which sent a direct message to one of Huntress' researchers.
The message asked for help with their upcoming conference and directed the recipient to a Google Doc featuring a custom sidebar designed to guide them through the execution of malware. The researcher recognized the lure as a scam but continued engaging with the actor to better understand their tactics.
When the researcher didn't fall for the malicious Google Doc, the threat actor followed up the next day with a second document that masqueraded as a Dropbox DocSend share and led to a counterfeit DocSend installer. This installer delivered AMOS stealer to macOS users, NetSupport RAT to Windows users, and a traffic-intercepting proxy.
Analysis of the malware revealed characteristics highly consistent with Atomic macOS Stealer (AMOS). Upon execution, it targets browser passwords and cookies, cryptocurrency wallets, keychain data, and Telegram files. The malware establishes persistence by making requests to specific URLs and sets up a polling backdoor agent.