[research] · · 1 min read
Attackers Exploit Google Docs App Script to Target Security Researchers
Huntress details a social engineering campaign that used a fake crypto conference and a manipulated Google Doc sidebar to trick cybersecurity professionals into installing cross-platform malware.
By ByteBulletin Editors · Editorial Team

AI-generated illustration · Z-Image-Turbo, self-hosted
Security firm Huntress has disclosed a sophisticated social engineering campaign that targeted cybersecurity professionals around the time of the Black Hat and Def Con conferences. The attackers, posing as representatives of a leading crypto news site, used the social media platform X to approach researchers with an invitation to a non-existent conference. The lure was designed to exploit the trust researchers place in legitimate collaboration tools, specifically Google Docs.
The core of the attack involved a Google Doc that appeared to be a standard planning document but contained a deceptive sidebar. This sidebar was designed to look like an encryption interface, prompting the target to enter a "decryption key" provided by the attacker. This interaction was the critical step in the compromise process. To build this custom user interface within a standard Google Doc, the attackers utilized Google Apps Script, a platform that allows developers to customize the UI with menus and sidebars.
Once the target engaged with the fake decryption prompt, the campaign aimed to install specific malware payloads tailored to the victim's operating system. For macOS users, the goal was to deploy an infostealer. For Windows users, the attackers attempted to install a remote desktop viewing tool repurposed as malware. Additionally, the campaign included a fake installer for the Ledger cryptocurrency wallet, indicating a focus on financial theft and credential harvesting.
The use of Google Apps Script to manipulate the document interface adds a technical layer to what is fundamentally a social engineering attack. It demonstrates how attackers are leveraging legitimate developer tools to bypass user skepticism. Security teams should be aware that standard collaboration platforms can be weaponized to create convincing phishing interfaces without requiring the victim to visit a malicious external site.
SHARE
RELATED

[research] ·
Frontier AI Labs Lack Public Containment Plans for Rogue Models
A new study by Guidelight AI Standards reveals that top AI companies have minimal public documentation for how they would shut down or restrict models that attempt to subvert human control.

[research] ·
arXivLabs: A New Framework for Collaborative Feature Development
arXiv has introduced arXivLabs, a platform enabling researchers and organizations to build and share new features directly on the website while adhering to strict privacy and community standards.

[research] ·
Grok Bypassed by 'Cryptographic Context Injection' Attack That Exfiltrates User Data
Researchers demonstrated that encrypting malicious instructions allows attackers to bypass Grok's static safety guardrails, forcing the model to leak chat history and personal data.