[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKUFRkQMtxCXE4ZhXM6uOguD5p8etYXT4UXMW6jXfA7c":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"fa91ac24-cea4-4730-9c37-ce1f56941363","fake-crypto-exec-weaponizes-google-doc-to-target-security-researcher-post-def-con","de6109a1-90b7-454b-b6db-af6174ce33f3","Fake Crypto Exec Weaponizes Google Doc to Target Security Researcher Post-DEF CON","A threat actor exploited social engineering tactics by impersonating a legitimate cryptocurrency media executive on X (Twitter) to establish trust with a Huntress security researcher, then delivered a malicious Google Doc as the attack payload. The timing — immediately after high-profile security conferences like DEF CON and Black Hat — was deliberate, as attendees are actively networking and more likely to engage with unknown contacts in a professional context. This attack highlights that even experienced security professionals are targeted with sophisticated pretexting campaigns, and that trusted platforms and file formats (Google Docs) can be weaponized to bypass skepticism. The incident underscores the critical need for identity verification practices and caution with unsolicited documents, regardless of the recipient's technical expertise.","**Immediate actions:**\n- Verify the identity of unsolicited contacts through an independent, out-of-band channel before engaging with any shared files or links.\n- Treat any unexpected document links — even from trusted platforms like Google Docs — as potentially malicious until confirmed safe.\n\n**Long-term improvements:**\n- Implement and regularly train staff on social engineering recognition, with specific scenarios covering post-conference networking impersonation tactics.\n- Establish a formal policy requiring dual-channel identity verification for all new professional contacts requesting document collaboration.\n- Create and maintain a documented incident response playbook specifically for social engineering and spear-phishing attempts targeting individual employees.\n\n**Detection measures:**\n- Deploy browser isolation or sandboxing tools to safely inspect unknown documents and URLs before full execution in a live environment.\n- Enable logging and alerting for access to cloud-hosted documents from newly contacted external parties to flag anomalous sharing patterns.",[12,13,14,15,16,17,18,19,20],"CIS Control 14 — Security Awareness and Skills Training","CIS Control 10 — Malware Defenses","NIST SP 800-50 — Security Awareness Training","NIST SP 800-61 — Computer Security Incident Handling Guide","NIST AT-2 — Literacy Training and Awareness","NIST IR-6 — Incident Reporting","MITRE ATT&CK T1566.003 — Phishing via Service (Spearphishing via third-party service)","MITRE ATT&CK T1disguise — Impersonation (T1656)","ITIL — Service Security and Incident Management","published","2026-08-19T16:21:26.820604+00:00","2026-08-19T16:21:26.509+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F08\u002F19\u002Ffake-crypto-exec-used-booby-trapped-google-doc-to-target-security-researcher-after-def-con\u002F?utm_source=rss&utm_medium=rss&utm_campaign=fake-crypto-exec-used-booby-trapped-google-doc-to-target-security-researcher-after-def-con","fake-crypto-exec-used-booby-trapped-google-doc-to-target-security-researcher-aft-0c3f3b","Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]