Home / Technology / Cybersecurity Pros Foil Google Docs-Based Hacking Attempt
Cybersecurity Pros Foil Google Docs-Based Hacking Attempt
21 Aug
Summary
- Hacker used Google Docs and Google App Script to deploy malware.
- Targeted cybersecurity professionals attending hacking conferences.
- Malware aimed to steal information or gain remote access.

Cybersecurity professionals recently defended against a novel hacking campaign that exploited Google Docs. The perpetrator, who posed as an employee of a crypto news outlet, approached cybersecurity experts on the social media platform X around the time of the Black Hat and Def Con conferences earlier this month. This individual attempted to trick targets into installing malware by using a legitimate-looking Google Doc with a deceptive sidebar.
The hacker's strategy involved a shared Google Doc, enhanced with Google App Script to simulate an encrypted document sidebar. Victims were prompted to enter a fake decryption key, a step designed to facilitate the installation of malware. This malicious software included an infostealer for macOS and a remote desktop tool repurposed as malware for Windows, alongside a fake installer for the cryptocurrency wallet Ledger.
Security firm Huntress detailed the campaign, noting that one of their researchers played along to gather intelligence. Hackers have historically targeted cybersecurity professionals, but this instance was notable for its sophisticated use of familiar Google platforms. The individual behind the malicious account did not respond to inquiries from TechCrunch.