logo

Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware

ID: d83084d7-776c-5e59-80dc-4d0a1f26d3f1

STIX ID: report--d83084d7-776c-5e59-80dc-4d0a1f26d3f1

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-08-19

Date Updated: 2026-08-26

...
...

Huntress researchers investigated a post-conference phishing campaign that used X (Twitter) DMs and trusted document/file-sharing services to distribute weaponized Google Docs and counterfeit DocSend installers; the lures delivered macOS AMOS stealer and multiple Windows payloads (NetSupport RAT, a TLS‑intercepting local proxy via a forged CA, and a Ledger wallet implant). The report details the attacker workflow, payload behaviors, persistence mechanisms, C2 infrastructure, indicators of compromise, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.