A threat actor targeted security researchers after Black Hat and DEF CON by impersonating a senior CoinDesk-linked cryptocurrency media executive on X and sending conference-planning lures through trusted services including Google Docs, GitHub Releases, and Dropbox DocSend. Huntress reported that the first lure used a booby-trapped Google Doc with a malicious Google Apps Script sidebar that asked victims for an "encryption key," profiled the host, and then steered users into staged malware delivery paths tailored to macOS and Windows systems.
On macOS, victims were served a disk image resembling Atomic macOS Stealer (AMOS), while Windows targets received a fake Google API Connector update that led to a ClickOnce application, PowerShell-based loaders, and additional payloads. Huntress said the Windows chain ultimately deployed NetSupport RAT, a fake Ledger wallet application, and a local TLS-intercepting proxy built around a rogue certificate authority, indicating goals that included credential theft, cryptocurrency wallet compromise, and persistent remote access; when the first attempt failed, the actor followed up with a second malicious document disguised as a DocSend share to continue the intrusion attempt.

Get the infrastructure and lures behind it.
15 events from the most recent confirmed update back to the earliest known activity.
On August 9, a threat actor using the X account @HartmansDoeke impersonated CoinDesk's VP and Head of Marketing and sent a direct message to a researcher about helping with an upcoming conference. Huntress said similar outreach was sent to multiple Black Hat and DEF CON attendees.
Using a honeypot account during the November 2025 campaign, Volexity observed subsequent attacker activity from a residential Comcast IP address in the United States that Spur associated with a proxy network.
In November 2025, Volexity observed broader spear-phishing from an attacker-created Gmail account targeting multiple customers. The emails linked to bsc2025[.]org, a fake Belgrade Security Conference site that selectively redirected targets into a Microsoft 365 phishing workflow.
During the October 2025 compromise, the attacker created a new device in Microsoft Entra ID named to match an existing victim device, apparently to maintain access after the phishing succeeded.
In October 2025, Volexity investigated a compromised Microsoft 365 account after anomalous login activity. The intrusion began with a spear-phishing email continuing a legitimate Belgrade Security Conference thread and led to attacker access to Microsoft 365 files.
Volexity had previously reported on the Russian threat actor UTA0355 in April 2025 before linking it to later phishing campaigns spoofing European security events.
In early 2025, Volexity published two blog posts about Russian threat actors abusing Microsoft 365 OAuth and Device Code authentication workflows, establishing the backdrop for later related campaigns.
After earlier malware-delivery attempts failed, the threat actor shifted tactics and offered funding of up to $1 million to keep the target engaged. Huntress assessed this may have been another pretext to steal credentials or personally identifiable information.
Huntress found the counterfeit DocSend installer for Windows fingerprinted the host, executed staged JavaScript in memory, and ultimately deployed NetSupport Manager RAT, a rogue certificate authority with local HTTPS interception capability, and a Ledger wallet implant.
The day after the initial failed attempt, the attacker sent a second malicious document masquerading as a Dropbox DocSend file share. This follow-on lure again delivered AMOS to macOS users and a Windows malware bundle to Windows users.
In the same campaign, the Windows path presented a fake Google API Connector update that led to a ClickOnce application signed with a likely stolen or fraudulently obtained certificate. The chain downloaded additional payloads including NetSupport RAT and other malware components.
In the first post-DEF CON lure, the macOS path either instructed users to run a terminal command or directed them to a GitHub Releases-hosted disk image, GAPIUpdate.dmg. Huntress found the payload closely matched Atomic macOS Stealer and included persistence and data theft capabilities.
After the X conversation began, the actor sent a Google Docs file that loaded a custom Google Apps Script sidebar and prompted the target for an attacker-supplied encryption key. The script collected victim information, sent updates through Telegram, and branched into separate macOS and Windows infection paths.
Talos observed a spike in activity for the Cyber Conflict-themed Seduploader campaign on October 7, 2023, indicating increased use of the malicious decoy document and malware delivery chain.
Cisco Talos reported that a new Group 74/APT28 campaign targeting people interested in cybersecurity likely started on October 4, 2023, using a Word decoy document themed around the Cyber Conflict U.S. conference.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
10 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourceitpro.com
Open sourcetechcrunch.com
Open sourcescworld.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourcevolexity.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.