Attacker weaponized Google Docs and Apps Script — not a zero-day — to phish security pros at Black Hat and DEF CON

Attacker weaponized Google Docs and Apps Script — not a zero-day — to phish security pros at Black Hat and DEF CON

An attacker targeting cybersecurity professionals around Black Hat and DEF CON in August 2026 used a legitimate Google Doc with a fake encryption sidebar built via Google Apps Script. No exploit was needed. Entering a supplied "decryption key" triggered AMOS infostealer on macOS or NetSupport RAT on Windows. TechCrunch reports the lure surpassed prior nation-state campaigns in convincingness. Huntress disclosed the campaign August 19.

Published

Read at another depth