Fake Conference Planning Google Doc Scam: Malware Update Trick Exposed

A message after a busy security conference can feel like one more introduction worth answering. This one started with a conversation about a future event.

The invitation led to a familiar document editor. What happened inside that document is the part readers need to understand before opening a similar invitation.

Illustrative reconstruction of a conference document with an unexpected update panel, not an actual attack screenshot

Overview

A conference connection that seemed to make sense

After Black Hat and DEF CON, people expect follow-up messages. Speakers, sponsors, researchers, and journalists exchange invitations while memories of the event are fresh.

That ordinary rhythm gave this fake conference planning Google Doc scam its opening. The first approach came through an X direct message, not a conventional email.

The sender appeared to represent CoinDesk and discussed an upcoming online conference. For a security researcher, that sounded plausible enough to inspect.

According to Huntress’s investigation, the account used a person’s photograph alongside another person’s name. That mismatch was one clue, not the whole case.

The researcher recognized the contact as suspicious and continued the conversation for analysis. The reported interaction is a documented attempt, not evidence that this researcher was infected.

The document became the pressure point

The actor shared a Google Doc styled as conference planning material and supplied an access key. The document appeared partly encrypted, inviting the recipient to unlock it.

Entering the supplied key failed. That failure mattered because a custom sidebar then framed the problem as something the reader needed to fix locally.

The sidebar offered a decryption process and a manual update. Both routes tried to move the recipient from reading a document toward running software.

A legitimate cloud document should not require an unrelated computer update merely to reveal an event agenda. That unexpected change in task is the central warning.

What was observed, and what remains uncertain

Huntress examined the document script, download paths, and a second DocSend-themed lure sent after the first approach failed.

Researchers identified an Atomic macOS Stealer-like payload in a disk image and a separate Windows chain involving a fake installer and remote-access components.

Some tested paths were broken or had already rotated. The macOS paste-command route entered a redirect loop during Huntress’s test, so it should not be described as successful.

The actor’s later document kept the pressure on. It imitated a secure file share and offered a supposed desktop viewer instead of a normal document.

  • The approach used post-conference networking as its believable context.
  • The Google Doc was a real document surface with attacker-controlled scripting.
  • The supplied key appeared to fail by design, creating a reason to install an update.
  • The macOS and Windows paths differed, so a single symptom list cannot cover both.
  • The targeted researcher did not install the malware during the reported exchange.

How the Fake Conference Planning Google Doc Scam Works

Step 1: A believable person opens a conversation after the event

The actor reached out when conference attendees were still expecting introductions. Timing made an unsolicited message less surprising than it would be months later.

The profile claimed a senior marketing connection at a recognized crypto publication. That identity was part of the lure, not a verified endorsement.

The early messages asked about future conference plans and an online event. They did not immediately demand passwords or money.

That slow opening matters. A person who has already discussed dates and speakers may treat the next document as a continuation, not a fresh security decision.

Look at the sender’s history, account age, name-image consistency, and contacts. None proves legitimacy alone, but contradictions deserve a separate verification channel.

If a conference organizer truly needs your help, confirm through a known company site or an established colleague. Do not use contact details supplied only in the DM.

Step 2: The recipient receives a familiar cloud document

The shared Google Doc carried conference-planning language. A familiar platform lowers suspicion because people use it every day for ordinary collaboration.

The dangerous part was not Google’s name. The document contained attacker-controlled Google Apps Script that displayed a custom sidebar to an authenticated user.

The script was able to manage the on-page flow and offer different paths for macOS and Windows. It also collected information useful to the operator.

Many readers would see a document first and consider scripts later, if at all. The familiar page becomes a wrapper for an unfamiliar request.

Opening a cloud document is not the same as authorizing a local installer. Treat the moment it asks for desktop action as a new, independent decision.

Do not let the address bar’s trusted document domain validate every instruction inside the file. User-created content on reputable services can still be malicious.

Step 3: A supplied key fails and creates a repair pretext

The actor gave the researcher an access key in the chat. When entered into the document’s panel, the key failed to reveal the promised content.

Huntress found that the apparent failure led to a decryption prompt and a manual update option. It looked like a technical inconvenience, not a new invitation.

That is the psychological hinge. A reader who believes they already passed the access check may focus on fixing the error instead of questioning it.

Cloud documents can legitimately have access restrictions. They do not need an unknown local program or shell command to unlock an event schedule.

When an access key fails, ask the organizer to share a readable copy using normal document permissions. A legitimate sender can resolve access without installing software.

If the response is another download or instructions to bypass a security warning, end the interaction. The friction is likely part of the plan.

Illustrative reconstruction of a failed document decryption prompt and manual update lure, not an actual attack screenshot

Step 4: The fake fix becomes a software installation request

On macOS, the sidebar offered a paste-and-run route and a separate disk-image download. The downloaded application was presented as a needed document update.

Huntress’s macOS command test hit a redirect loop, so that route did not demonstrate a completed infection in the lab.

The manual download was different. Static analysis found behavior consistent with Atomic macOS Stealer, including interest in browser data, wallets, and keychain information.

The instructions also pushed the user past a macOS security warning. A request to override Gatekeeper for a conference document is particularly telling.

On Windows, the sidebar directed users toward a supposed connector update. Another route used a signed ClickOnce package to start installation from actor-controlled infrastructure.

The installation window could look routine while further content loaded. A signature on one component did not establish that the document sender or package was trustworthy.

Do not copy commands from an unexpected document into Terminal, PowerShell, or the Run box. A legitimate planning file has no reason to ask.

Step 5: A second document keeps the target engaged

When the first lure did not produce an installation, the actor followed up the next day. The new material imitated a Dropbox DocSend share.

The page claimed a desktop version was needed to view the file. That is another shift from a document-reading task to a software-execution task.

The site checked whether the visitor appeared to be on a Mac or Windows computer and served different installer paths.

For macOS, Huntress found a ZIP containing the same stealer family seen in the earlier route. Windows visitors received a counterfeit DocSend installer.

The Windows application displayed a polished onboarding sequence using familiar marketing language. No legitimate Dropbox software was installed by that package.

A busy recipient might interpret the smooth screens as proof the download worked. In this case, they were scenery while the underlying loader performed other actions.

A genuine document share should open through the provider’s normal web experience. Verify any desktop-app claim directly with that provider, never through the shared file’s landing page.

Step 6: The payload can reach beyond the document

The macOS sample aimed at saved browser information, cookies, wallets, keychain data, and other sensitive material. That is far beyond anything needed for conference planning.

Huntress also analyzed Windows payloads associated with the wider operation, including NetSupport configured for covert remote access and a component aimed at Ledger users.

Some infrastructure was unavailable when the researchers tested it. Those limits matter: an identified payload chain is not a verified count of infected attendees.

The risk to an individual is nevertheless serious. If a suspicious file was run, the computer may no longer be a safe place to change passwords or access wallets.

Remote access can also expose company documents or sessions. A work laptop needs its security team involved before cleanup destroys useful evidence.

The attack is not evidence that CoinDesk, Google Docs, or Dropbox DocSend are scams. Their identities or surfaces were borrowed to make the instruction look familiar.

Why the Document Looks Safer Than It Is

People judge a message by the platform around it. A recognized document editor, familiar sharing language, and a plausible conference topic all contribute to trust.

Here, the document editor was simply a stage. The attacker controlled the content and the custom sidebar that converted an access problem into an update demand.

The supplied key was another credibility cue. It made the interaction feel private and deliberate, even though the apparent error pushed the user toward malware.

Technical users are not immune. A security researcher might be curious about a conference agenda and accustomed to troubleshooting broken software.

The right question is not whether the page is familiar. Ask whether this specific task normally requires the requested action on your computer.

For an event document, the answer should be no. Permissions can be fixed by the owner; a device-wide update is not the remedy.

How to Check an Invitation Before Opening Its Files

Start with the human claim. Search for the organizer through its official site and compare the sender’s role with information you can independently verify.

Message the person through an established account or a known company address. Avoid replying to the same suspicious handle as your only check.

Look for a concrete event name, venue or platform, agenda, and contact person. Vague planning language can be reused across many targets.

If the document asks for a key, request normal access permissions or a plain PDF from the verified organizer. Do not troubleshoot by installing software.

Inspect downloaded file types before opening them. A document share should not quietly become a disk image, installer, archive, or command script.

Ask a security colleague to review the invitation if it reached a work account. Early reporting can protect other attendees receiving the same outreach.

Do not assume a popular professional event endorses everyone who mentions it afterward. Attackers reuse event names because legitimate networking creates openings.

What to Do if You Followed the Fake Conference Document Instructions

  1. Stop interacting with the document and preserve the message. Do not run a second installer to test the first. Save the X conversation, document link, file names, and approximate times.
  2. If you only opened the document, report the lure. Opening alone is not proof of infection. Tell your security team what appeared and whether you entered a key or downloaded anything.
  3. If you ran a file or command, isolate the device. Disconnect its network connection and stop using it for email, banking, and wallets. Contact workplace incident responders before deleting evidence.
  4. Secure accounts from another trusted device. Change important passwords, revoke suspicious sessions, and review multifactor settings. Prioritize email, cloud storage, company access, and financial accounts.
  5. Treat crypto secrets as exposed when warranted. If a wallet was accessible on the affected machine, move assets to a newly created wallet from a clean device. An exposed seed phrase cannot be repaired by changing a password.
  6. Scan and rebuild according to the exposure. Malwarebytes can help identify unwanted software, but a professional reimage may be safer after a confirmed stealer or remote-access infection. An ad blocker such as AdGuard reduces future malicious-page exposure, not an existing compromise.
  7. Watch for a second approach. The actor in this case changed from a Google Doc to a DocSend-themed lure. Warn teammates and conference contacts without forwarding a live malicious link.

Frequently Asked Questions

Is every encrypted Google Doc a scam?

No. The warning here is the combination of a failing supplied key and instructions to install software or run a command to read ordinary event material.

Did the Huntress researcher get infected?

No. Huntress says the researcher recognized the message as suspicious and continued the conversation to investigate the attempted attack.

Is CoinDesk involved in this campaign?

The attacker claimed to represent CoinDesk. The investigation describes impersonation, not a verified relationship with the publication.

What if I clicked the document but installed nothing?

Record what happened and report it. Clicking a link is not the same as executing the offered software, but account and device context still deserve review.

Why would a fake document ask for an update?

The update story gives a reason to run code unrelated to the original task. It turns an access problem into a malware-installation opportunity.

Can security software catch this automatically?

Some components may be detected, but changing downloads and user-approved execution reduce certainty. Prevention begins with refusing the unexpected installation request.

The Bottom Line

This fake conference planning Google Doc scam borrowed the rhythm of real post-event networking, then used a staged document error to request local software.

If an invitation cannot be read without a manual update, stop and verify the sender independently. A legitimate agenda is not worth bypassing your computer’s safeguards.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Brazil Government Search Results Hijacked for Fake Gambling Apps Exposed

Next

Payment Plan PDF Email Scam: Global Group Ransomware Delivery Explained