Black Hat and DEF CON conference participants began to be lured into fake projects through Google Docs, and then try to infect their computers with malware. One of the targets was a Huntress specialist who recognized the deception and continued to communicate with the attacker to trace how the malware infects the computer at each stage.
As Huntress found out, on August 9, the attacker contacted the company's employee through personal messages in X, having submitted to the marketing manager CoinDesk. The interlocutor offered to help prepare a future online conference, and then sent a Google document and a key to “decrypt” it. Other conference participants received similar messages.
The document contained a sidebar created with Google Apps Script. The entered key was not intentionally triggered, after which the user was offered to “correct” the problem. The script collected information about the computer, transmitted the victim's actions through Telegram and chose a further scenario depending on the operating system.
On macOS, the user was persuaded to execute the command in the terminal or manually install the image GAPIUpdate.dmg. The program asked to bypass the built-in protection of Gatekeeper and enter the password. Sample analysis showed signs of the Atomic macOS Stealer (AMOS) infostiler, which steals passwords and browser cookies, key bundle data, information from cryptocurrency wallets, Telegram and the Notes app. The malware also installed a component for permanent remote access to the system.
Another scheme was used for Windows. After a fictitious decryption error, the victim was offered to update the supposedly necessary “Google API Connector”. The installer used ClickOnce and showed a fake Google Workspace Marketplace page while additional components were loading in the background. An alternative option forced the user to insert the PowerShell command on his own.
When the first attempt did not work, the intruder sent another document the next day. This time, the bait simulated the Dropbox DocSend file and offered to install the desktop version of the service. The same AMOS was downloaded for macOS, and Windows users were given a fake DocSendInstaller.exe. The program was signed by the stolen Discord certificate, but the digital signature could not be confirmed.
After launch, the Windows version collected the username and computer, the OS version, processor, graphics card, BIOS, memory, network adapters and keyboard layouts. Then three components were loaded. The first was the NetSupport Manager version, configured to stealthically remotely manage the system. The second installed his own root certificate, redirected the appeals to VirusTotal to the local proxy server and allowed to replace the results when the files were checked. A third was looking for the installed cryptocurrency wallet Ledger and created a channel to get teams.
Huntress has published compromising indicators. Experts advise to consider an unexpected request to execute the command in the terminal, disable system protection or manually install the “update” of a possible attack. If the malicious command has already been executed, the computer should be disconnected from the network, complete active sessions, change passwords and access keys, and check cryptocurrency wallets.
As Huntress found out, on August 9, the attacker contacted the company's employee through personal messages in X, having submitted to the marketing manager CoinDesk. The interlocutor offered to help prepare a future online conference, and then sent a Google document and a key to “decrypt” it. Other conference participants received similar messages.
The document contained a sidebar created with Google Apps Script. The entered key was not intentionally triggered, after which the user was offered to “correct” the problem. The script collected information about the computer, transmitted the victim's actions through Telegram and chose a further scenario depending on the operating system.
On macOS, the user was persuaded to execute the command in the terminal or manually install the image GAPIUpdate.dmg. The program asked to bypass the built-in protection of Gatekeeper and enter the password. Sample analysis showed signs of the Atomic macOS Stealer (AMOS) infostiler, which steals passwords and browser cookies, key bundle data, information from cryptocurrency wallets, Telegram and the Notes app. The malware also installed a component for permanent remote access to the system.
Another scheme was used for Windows. After a fictitious decryption error, the victim was offered to update the supposedly necessary “Google API Connector”. The installer used ClickOnce and showed a fake Google Workspace Marketplace page while additional components were loading in the background. An alternative option forced the user to insert the PowerShell command on his own.
When the first attempt did not work, the intruder sent another document the next day. This time, the bait simulated the Dropbox DocSend file and offered to install the desktop version of the service. The same AMOS was downloaded for macOS, and Windows users were given a fake DocSendInstaller.exe. The program was signed by the stolen Discord certificate, but the digital signature could not be confirmed.
After launch, the Windows version collected the username and computer, the OS version, processor, graphics card, BIOS, memory, network adapters and keyboard layouts. Then three components were loaded. The first was the NetSupport Manager version, configured to stealthically remotely manage the system. The second installed his own root certificate, redirected the appeals to VirusTotal to the local proxy server and allowed to replace the results when the files were checked. A third was looking for the installed cryptocurrency wallet Ledger and created a channel to get teams.
Huntress has published compromising indicators. Experts advise to consider an unexpected request to execute the command in the terminal, disable system protection or manually install the “update” of a possible attack. If the malicious command has already been executed, the computer should be disconnected from the network, complete active sessions, change passwords and access keys, and check cryptocurrency wallets.