A recent phishing attempt showed how social engineering is evolving inside the cybersecurity world. A person posing as a representative of a major crypto news outlet reached out to security professionals around the time of Black Hat and Def Con, using social media messages and replies to start contact.
According to Huntress, the campaign then shifted to a seemingly ordinary Google Doc that was presented as a planning file for a fictional crypto conference. The document included a side panel designed to look encrypted, nudging the target to enter a fake decryption key.
That step was meant to open the door to malware installation on either macOS or Windows, depending on the device. Researchers said the attacker also used Google App Script to make the interface appear more convincing by adding custom elements inside the document.
The campaign reportedly tried to deliver an infostealer for Apple systems, a remote desktop tool adapted for Windows, and a counterfeit installer for the Ledger crypto wallet. Huntress said one of its researchers engaged with the attacker to better understand the method.
The case highlights how trusted productivity tools can be repurposed in sophisticated lures, especially when they are paired with timely event references and realistic messaging. As digital trust becomes more central to online work, security awareness will likely keep evolving alongside the tools people use every day.