Security2 distinct publishers3 min readUpdated
Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.
A Huntress researcher returning from Black Hat and Def Con this summer was approached on X by someone posing as CoinDesk's VP and head of marketing, asking for help with a conference that did not exist [1][2][3]. The researcher played along, and the actor sent over a Google Doc dressed up as a planning document [4][5]. That document was the attack.
According to the Huntress post published on August 19, if an authenticated Google user opened the file, a custom Google Apps Script sidebar was presented alongside the document [1][6]. The doc asked for an "encryption key," which the actor supplied over DM and which appeared to fail when entered [7]. The failure was the pretext. The sidebar then offered two ways forward: ClickFix-style instructions, and a download option, both intended to download and execute malicious code [8].
The operational point is the location of the malicious content. Contact happened in social media DMs and the instructions rendered inside a document hosted by Google, so there was no mail hop for a gateway to inspect and no attachment to detonate in a sandbox [16]. What the target saw was a legitimate Google Docs session with a legitimate Google Docs feature attached to it. Huntress framed the whole thing as workflow construction: by combining social media DMs with trusted document and file-sharing services, the actor built a legitimate-looking workflow designed to get the target to run malware [11].
The researcher did not bite, and the actor came back the next day with a second document, this one disguised as a Dropbox DocSend share and leading to a counterfeit DocSend installer [9]. Payload selection was by platform: AMOS infostealer on macOS, and on Windows an implant built to drain Ledger wallets plus a traffic-intercepting proxy meant to defeat security software and checks that rely on VirusTotal [10]. That last component is the tell that this is not opportunistic spray. Someone budgeted engineering time to break the exact verification step a careful person performs before running an unfamiliar installer.
When the second lure failed too, the actor pivoted again and asked the researcher whether they knew anyone looking for funding of up to $1m, which Huntress hypothesised was another pretext to harvest credentials or personal data [12].
Huntress's guidance for anyone recently back from a conference is behavioural rather than indicator-based: treat any plausible message that ends in a document or installer asking you to do something your security controls would normally block as hostile [13]. Unexpected requests to run terminal commands, bypass Gatekeeper, install a manual update, or type a device password are compromise attempts, not troubleshooting [14]. If someone did interact, the vendor's steps are to isolate the host, collect evidence and consider reimaging, assume credentials are gone, revoke sessions, reset passwords, rotate API keys and other secrets on the system, and review any cryptocurrency wallets [15].
Two things to watch. Whether your Drive telemetry and Apps Script controls can even tell you that a shared external document ran a script container in one of your users' sessions, since the sidebar was the delivery surface [6][8]. And whether the DocSend-styled installer chain shows up against targets who never went to a conference, which would mark the conference-attendee framing as a warm-up rather than the campaign [9][10].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Huntress published a blog post on August 19 detailing malicious outreach targeting a security researcher after Black Hat / Def Con.
A researcher for Huntress was targeted on X following Black Hat / Def Con this summer.
The threat actor masqueraded as CoinDesk's VP and head of marketing and first asked the researcher for help with a fictitious upcoming conference.
The researcher spotted the scam but expressed interest in order to better understand the tactics being used.
The actor subsequently sent the researcher a Google Doc disguised as a planning document for the supposed conference.
Huntress said that if an authenticated Google user opened the document, a custom Google Apps Script sidebar was presented alongside the document.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor forensics, single primary source
The mechanism is described concretely and consistently by two independent outlets: container-bound Apps Script rendering a sidebar for authenticated viewers, the fake key prompt, dual ClickFix/download paths, named payloads (AMOS, NetSupport RAT), named delivery infrastructure (GitHub Releases, docsend[.]online, ClickOnce manifest) and persistence details. SC Media adds direct emailed explanation from a named Huntress analyst. Ceiling is set by everything tracing back to one vendor blog with no independent replication, no published hash/IOC list in these sources, and one article truncated mid-sentence with a Windows payload enumeration that differs from the other outlet's summary.
Live technique, one documented target, no confirmed victims
There is real-world activity: outreach was observed against several Black Hat/DEF CON attendees, infrastructure was live enough to serve payloads, and the Windows ClickOnce stage plus C2 infrastructure overlaps with a separately reported campaign and the Sleestak loader. But the only fully documented interaction is with a researcher who deliberately engaged and never executed anything, no victim or compromise counts are published, and several stages were already broken or de-hosted at analysis time - so spread of actual impact is unquantified.
Framing runs slightly ahead of the documented harm
Both headlines generalise from one observed interaction to 'Def Con attendees targeted' by a 'persistent phishing campaign', and neither quantifies contacted or compromised users; Infosecurity omits that the macOS ClickFix command was misconfigured and several payload endpoints were dead. Against that, the technical substance is genuinely novel and under-appreciated - Apps Script sidebars rendering attacker HTML with no email hop is a real inspection blind spot - and SC Media reports the failures candidly, so the overstatement is modest rather than promotional.
Single-vendor research with clear commercial upside
Huntress is both the sole primary source and a commercial security vendor whose researcher is the protagonist; the disclosure ends in vendor-branded guidance and a remediation checklist, and SC Media's added detail comes from a Huntress Principal Security Operations Analyst by email. That is normal, useful vendor research rather than disguised marketing, and neither outlet pitches a product, but no non-vendor party (Google, Dropbox, GitHub, X, CoinDesk, an independent IR firm) is quoted to counterbalance it.
Mechanism solid, scale and Windows chain less so
High confidence in the core technique and the macOS path, which two outlets describe consistently with named tooling and platform mechanics. Lower confidence in the Windows payload inventory (differing enumerations, one body truncated), in the incident timeline ('next day' versus 'after some time'), in the key-prompt label, and in anything about scale or takedown status, none of which the supplied sources establish.
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
security
ClickFix operators install the signed Deno runtime to run their remote JavaScript1 distinct publisher
security
A staging password went into a Google Doc, and Google's autocomplete found it first1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026
1 article · August 20, 2026