A threat actor impersonated a CoinDesk marketing executive in X direct messages, using post-Black Hat and DEFCON cryptocurrency-conference lures to target security researchers. The messages linked to legitimate Google Docs containing container-bound Google Apps Script that profiled visitors and sent their IP address, geolocation, browser details, and cryptocurrency-wallet-extension data to the operator through Telegram.
The campaign routed victims to operating-system-specific malware: macOS users received a variant of the AMOS infostealer, while Windows users were served an encoded PowerShell loader chain and installers signed with three stolen or fraudulently issued certificates. Recovered Windows components included a malicious NetSupport Manager deployment, a persistent rogue local certificate authority capable of TLS interception, and a Ledger-wallet-focused implant. Russian-language comments and C2 artifacts indicate the operator may be Russian-speaking, but no threat group has been attributed.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Social-media users reported suspected scam activity associated with the X account impersonating a CoinDesk marketing executive as early as October 2025.
The Windows loader captured a desktop screenshot, retrieved password-protected archives from actor infrastructure, and launched payloads including a maliciously configured NetSupport Manager installation, a persistent rogue local certificate authority and TLS-intercepting proxy, and a Ledger-wallet-focused implant. The rogue-PKI component used a stolen Lenovo certificate, installed a fake Google Trust Services root CA, and persisted its CA, hosts-file, and firewall-rule changes across reboots.
Windows victims were directed to a fake Google API Connector delivered through ClickOnce and signed with a suspected stolen or fraudulently issued Norwegian-company certificate, or to an encoded PowerShell ClickFix chain. A separate Dropbox DocSend lure supplied a fake DocSend desktop application bearing a non-validating stolen Discord certificate signature.
macOS visitors were offered either a piped zsh ClickFix command or a DMG download from the actor's GitHub repository. The delivered macOS malware appeared to be an AMOS infostealer variant using Gatekeeper-bypass instructions and a password prompt.
The actor's legitimate Google Docs contained a container-bound Apps Script sidebar that collected viewers' IP address, geolocation, browser details, and cryptocurrency-wallet-extension presence upon opening. The script relayed profiling data and action beacons through the Telegram API without an OAuth consent prompt.
A threat actor using @HartmansDoeke, while posing as CoinDesk's VP and Head of Marketing, contacted multiple security researchers near the end of DEFCON with cryptocurrency-conference lures and links to alleged planning material.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.