
Threat actor posed as a CoinDesk VP, used a rigged Google Doc and fake Ledger installer to target security researchers with AMOS infostealer and NetSupport RAT.
A social engineering campaign used Google Docs, custom malware, and a fictitious cryptocurrency panel to lure security professionals into downloading infostealers and remote access tools. The attack ran for roughly 11 days before being exposed.
Someone pretending to be a senior CoinDesk executive spent the weeks after Hacker Summer Camp hunting the hunters. A threat actor operating under the X handle @HartmansDoeke impersonated CoinDesk's vice president and reached out to multiple cybersecurity researchers around August 9, 2026, pitching them on participation in a fake online conference about cryptocurrency. The lure was a Google Doc rigged with a custom Google Apps Script designed to fingerprint victims' machines and deliver platform-specific malware, researchers at Huntress said.
Initial contact came via public replies and direct messages on X. The attacker invited targets to join what appeared to be a legitimate panel discussion on crypto topics, a reasonable proposition given that these researchers had just attended Black Hat and DEF CON in Las Vegas. Once a target showed interest, they were directed to a Google Doc that looked like a conference brief. Embedded inside was a Google Apps Script that quietly collected host information, including operating system details, and reported the activity back to the attacker via Telegram, Huntress said.
For macOS users, the payload was a variant of the Atomic macOS Stealer, commonly known as AMOS. This infostealer is designed to vacuum up passwords, browser cookies, crypto wallet credentials, and keychain data from Apple machines. For Windows users, the attacker deployed the NetSupport RAT, a legitimate remote administration tool that's been repurposed by criminals for years, alongside a fake Ledger wallet installer.
The campaign didn't stop at the Google Doc. Huntress identified a subsequent lure featuring a counterfeit installer hosted on server infrastructure controlled by the attacker. Huntress and TechCrunch publicly reported the campaign on August 20, 2026, roughly 11 days after the initial outreach began. The X account used in the impersonation has since been flagged.
This isn't the first time threat actors have gone after the cybersecurity community directly. North Korea's Lazarus Group ran a similar campaign in 2021, creating fake researcher personas and booby-trapped Visual Studio projects to compromise security professionals. The use of a fake Ledger installer is particularly concerning for hardware wallet users. Ledger has been a frequent target of phishing campaigns since its customer database was breached in 2020, and counterfeit apps continue to surface across platforms.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.