Skip to content

Security2 publishers3 min readPublished

ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload

Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload
Photo: huntress.com

What happened

  • Huntress published a blog post on August 19 detailing malicious outreach targeting a security researcher after Black Hat / Def Con.
  • A researcher for Huntress was targeted on X following Black Hat / Def Con this summer.
  • The threat actor masqueraded as CoinDesk's VP and head of marketing and first asked the researcher for help with a fictitious upcoming conference.
  • The researcher spotted the scam but expressed interest in order to better understand the tactics being used.
  • The actor subsequently sent the researcher a Google Doc disguised as a planning document for the supposed conference.

Compiled by The WatchSomething wrong?How this is made

Why it matters

A Huntress researcher returning from Black Hat and Def Con this summer was approached on X by someone posing as CoinDesk's VP and head of marketing, asking for help with a conference that did not exist [1][2][3]. The researcher played along, and the actor sent over a Google Doc dressed up as a planning document [4][5]. That document was the attack.

According to the Huntress post published on August 19, if an authenticated Google user opened the file, a custom Google Apps Script sidebar was presented alongside the document [1][6]. The doc asked for an "encryption key," which the actor supplied over DM and which appeared to fail when entered [7]. The failure was the pretext. The sidebar then offered two ways forward: ClickFix-style instructions, and a download option, both intended to download and execute malicious code [8].

The operational point is the location of the malicious content. Contact happened in social media DMs and the instructions rendered inside a document hosted by Google, so there was no mail hop for a gateway to inspect and no attachment to detonate in a sandbox [16]. What the target saw was a legitimate Google Docs session with a legitimate Google Docs feature attached to it. Huntress framed the whole thing as workflow construction: by combining social media DMs with trusted document and file-sharing services, the actor built a legitimate-looking workflow designed to get the target to run malware [11].

The researcher did not bite, and the actor came back the next day with a second document, this one disguised as a Dropbox DocSend share and leading to a counterfeit DocSend installer [9]. Payload selection was by platform: AMOS infostealer on macOS, and on Windows an implant built to drain Ledger wallets plus a traffic-intercepting proxy meant to defeat security software and checks that rely on VirusTotal [10]. That last component is the tell that this is not opportunistic spray. Someone budgeted engineering time to break the exact verification step a careful person performs before running an unfamiliar installer.

When the second lure failed too, the actor pivoted again and asked the researcher whether they knew anyone looking for funding of up to $1m, which Huntress hypothesised was another pretext to harvest credentials or personal data [12].

Huntress's guidance for anyone recently back from a conference is behavioural rather than indicator-based: treat any plausible message that ends in a document or installer asking you to do something your security controls would normally block as hostile [13]. Unexpected requests to run terminal commands, bypass Gatekeeper, install a manual update, or type a device password are compromise attempts, not troubleshooting [14]. If someone did interact, the vendor's steps are to isolate the host, collect evidence and consider reimaging, assume credentials are gone, revoke sessions, reset passwords, rotate API keys and other secrets on the system, and review any cryptocurrency wallets [15].

Two things to watch. Whether your Drive telemetry and Apps Script controls can even tell you that a shared external document ran a script container in one of your users' sessions, since the sidebar was the delivery surface [6][8]. And whether the DocSend-styled installer chain shows up against targets who never went to a conference, which would mark the conference-attendee framing as a warm-up rather than the campaign [9][10].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories