Find notable cyber news and cases, enriched with sources, timelines, and signals.

Black Hat / Def Con attendee phishing campaign with Google Doc and DocSend lures

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A persistent phishing campaign used fake post-conference outreach and trusted file-sharing lures to target cybersecurity conference attendees, creating a path to credential theft and malware execution after Black Hat / Def Con. The actor first posed as CoinDesk's VP and head of marketing on X and then sent a Google Doc with a malicious Google Apps Script sidebar. When that did not work, the actor followed up with a Dropbox DocSend-style lure that delivered a counterfeit installer with platform-specific payloads, including AMOS on macOS. The sequence shows a repeated operation designed to keep targets engaged and trick them into running code.

Related Happenings

Fake Bank of America phishing remote-control campaign

Campaign
H score32 First: 05.08.2026 11:00 Last: 05.08.2026 11:00 Sources 1

About this happening: The fake Bank of America phishing campaign is delivering a multi-stage download chain that can install ScreenConnect and give attackers remote control of victim sy...

LogoKit real-time per-victim phishing campaign

Campaign
H score35 First: 29.07.2026 19:00 Last: 29.07.2026 19:00 Sources 1

About this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

GPPStorm Google Partners enrollment phishing campaign

Campaign
H score33 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...

REF8372 malicious Google Ads CastleStealer delivery campaign

Campaign
H score27 First: 22.06.2026 16:20 Last: 22.06.2026 16:20 Sources 1

About this happening: The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...

Timeline

  1. 20.08.2026 12:30 2 articles · 1h ago

    Persistent phishing campaign targets cybersecurity conference attendees

    Initial Disclosure

    Huntress described a persistent phishing campaign that used post-conference outreach on X, a fake CoinDesk VP and head of marketing pretext, a malicious Google Doc with a custom Google Apps Script sidebar, and a counterfeit Dropbox DocSend installer to target a researcher after Black Hat / Def Con. The lure chain was designed to keep the target engaged and trick them into running code, with payloads that included AMOS on macOS and, on Windows, an implant aimed at stealing cryptocurrency from Ledger wallets plus a traffic-intercepting proxy to help evade security checks.

    Show sources