Google Docs Used in Phishing Campaign to Install Rogue Certificate Authority
A phishing campaign targeting cybersecurity conference attendees has been using Google Docs and other familiar online services to deliver malware, including a Windows payload that can install its own trusted certificate authority on compromised PCs.
The researchers from cybersecurity firm Huntress published a report on August 19 after one of their own researchers was contacted following Black Hat and DEF CON. The attacker posed as CoinDesk's vice president and head of marketing on social media platform X, asking for help with an upcoming conference.
Rather than directing the target to a conventional phishing page, the attacker sent a Google Doc containing a custom Google Apps Script sidebar. The document appeared partially encrypted and asked the recipient to enter an 'encryption key' supplied by the attacker.