Skip to content
Back to Guavy Wire
Stocks

Google Docs Used in Phishing Campaign to Install Rogue Certificate Authority

Instruments
GOOGL
Share

A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own trusted certificate authority on compromised PCs.

The researchers from cybersecurity firm Huntress published a report on August 19 after one of their own researchers was contacted following Black Hat and DEF CON. The attacker posed as CoinDesk's vice president and head of marketing on social media platform X, asking for help with an upcoming conference.

Rather than directing the target to a conventional phishing page, the attacker sent a Google Doc containing a custom Google Apps Script sidebar. The document appeared partially encrypted and asked the recipient to enter an 'encryption key' supplied by the attacker.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc