Hackers Use Fake Crypto Conference Invite to Target Security Researchers With Google Docs Malware

Hackers Use Fake Crypto Conference Invite to Target Security Researchers With Google Docs Malware

TL;DR

  • Hackers impersonating journalists from major crypto news outlets are sending fake conference invitations to cybersecurity researchers, using weaponized Google Docs links to deliver credential-stealing malware.
  • The campaign exploits trust in Google Docs and the professional relevance of crypto events to bypass suspicion, specifically targeting security researchers for their high-value access and intelligence.
  • Experts warn the attack highlights a rise in highly personalized social engineering and recommend verifying invites out-of-band, inspecting document permissions, and isolating research environments to prevent compromise.

A Sophisticated Trap Disguised as Opportunity

A new social engineering campaign is making the rounds in the cybersecurity community, and it flips the usual script. Instead of targeting crypto investors or everyday users, threat actors are going after the defenders themselves. Researchers have uncovered an operation where hackers pose as journalists from well-known cryptocurrency news publications to lure security professionals with exclusive invitations to a fake crypto conference.

The lure is effective because it is highly personalized and professionally relevant. Victims receive a polished email, often from a spoofed or lookalike domain, claiming to be a reporter seeking expert commentary or offering a speaker slot at an upcoming blockchain security summit. The correspondence is well-written, references the target's recent work, and builds credibility before delivering the payload.

Weaponizing Google Docs for Stealth Delivery

The core of the attack is not a suspicious attachment, but a seemingly harmless Google Docs link. Rather than sending a malware-laden file directly, which would likely be flagged by email security filters, the attackers weaponize a trusted platform.

Victims are directed to a Google Doc that appears to contain the conference agenda, speaker list, or interview questions. The document itself may be empty or contain generic text, but it prompts the user to click on another embedded link, image, or "View Comments" notification to access the full details. That second click leads to an external site hosting malware, or triggers an OAuth permission request that grants the attacker access to the user's Google account.

In some variants, the attackers exploit Google Docs' comment and mention feature. A target receives a legitimate notification from Google that they have been mentioned in a document, which makes the invitation look authentic and bypasses email authentication checks like SPF and DKIM entirely. Once clicked, the document uses obfuscated JavaScript or redirects through services like Google Translate or AppScript to deliver an information stealer designed to harvest credentials, browser cookies, and authentication tokens.

Why Target Security Researchers?

At first glance, targeting cybersecurity professionals seems counterintuitive. They are typically the most vigilant users and hardest to fool. However, that is precisely what makes them valuable.

Researchers often have privileged access to threat intelligence, vulnerability research, private malware samples, and corporate networks. Compromising a single researcher can provide attackers with a foothold into a security firm, a pathway to discover how their own malware is being detected, or credentials that can be used to launch more convincing supply-chain attacks against that researcher's clients and contacts.

There is also a strategic motive. Groups linked to state-sponsored actors, particularly those focused on cryptocurrency theft, have a history of targeting researchers who investigate their operations. Gaining access to a researcher's communications can tip off attackers that they are under investigation and allow them to adapt their tactics before being exposed.

Anatomy of the Social Engineering Playbook

This campaign succeeds because it exploits human psychology more than technical flaws. Several key tactics make it stand out:

  1. Authority and Impersonation: By posing as journalists from reputable outlets like CoinDesk, The Block, or Decrypt, attackers borrow instant credibility. Researchers are accustomed to interacting with the press and are less likely to scrutinize a media inquiry.
  2. Relevance and Flattery: The invitation is tailored. It cites the victim's recent blog post, conference talk, or CVE disclosure and offers a prestigious opportunity, lowering the target's guard by appealing to professional reputation.
  3. Trust in Familiar Infrastructure: People inherently trust notifications from Google Docs, Slack, or other collaboration tools. Hosting the initial lure on Google's infrastructure makes the link appear safe to both humans and automated security scanners.
  4. Multi-Stage Engagement: The attackers do not ask for anything malicious in the first email. They build a short rapport over one or two replies before sending the Docs link, making the interaction feel like a legitimate conversation rather than a cold phishing attempt.

How to Spot and Stop the Attack

Defending against this type of highly targeted phishing requires a shift from simply scanning for bad links to verifying context and behavior.

Verify Out-of-Band: Never trust contact information provided in the same email thread. If you receive a conference invite or press inquiry, independently look up the publication's official contact page and reach out to the journalist through a verified email or social media account to confirm the request.

Scrutinize Google Docs Permissions: Be wary of any Google Doc that immediately asks you to click an external link, enable a script, or grant OAuth permissions to a third-party app to view the content. A legitimate agenda or question list should be visible directly in the document without extra steps. Check the document owner's email address carefully for slight misspellings or generic Gmail accounts.

Isolate and Inspect: Open unsolicited documents in an isolated environment, such as a virtual machine or a browser profile with no logged-in sessions or stored credentials. Hover over all links to preview the true destination URL before clicking, and be suspicious of URL shorteners or redirect services.

Adopt a Zero-Trust Mindset for Invites: Treat every unexpected invitation, even from a seemingly trusted source, as potentially hostile. Security teams should establish a clear protocol for handling external media requests and conference invites, including mandatory verification for any link that leads outside the organization's domain.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
Hackers Use Fake Crypto Conference Invite to Target Security Researchers With Google Docs Malware Hackers Use Fake Crypto Conference Invite to Target Security Researchers With Google Docs Malware Reviewed by Randeotten on 8/21/2026 05:49:00 AM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.