Def Con Attendees Targeted by Persistent Phishing Campaign
ID: 9de14b99-f0f7-5c86-b8ef-2008a6ca7d4f
STIX ID: report--9de14b99-f0f7-5c86-b8ef-2008a6ca7d4f
Feed Name: Infosecurity Magazine (News)
Threat Score
Huntress warns conference attendees about a targeted phishing campaign that used impersonation, malicious Google Docs (with a custom Apps Script sidebar), and fake DocSend installers to deliver malware — including the AMOS infostealer for macOS and a Windows implant that steals Ledger cryptocurrency and uses a proxy to evade detection — and advises isolating affected systems, collecting forensics, rotating credentials and secrets, and reviewing cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
