Huntress details CoinDesk impersonation malware campaign targeting cybersecurity researchers on X

A threat actor using the X handle @HartmansDoeke impersonated CoinDesk’s vice president and contacted multiple cybersecurity researchers around August 9, 2026, after Black Hat and DEF CON in Las Vegas. The attacker invited targets to a fake cryptocurrency conference and directed them to a legitimate-looking Google Doc containing custom Google Apps Script malware designed to identify their devices and support delivery of platform-specific malware. Huntress, whose researcher engaged the attacker without executing a payload, said macOS users were targeted with Atomic macOS Stealer, or AMOS, while Windows users faced NetSupport RAT and a counterfeit Ledger wallet installer. The incident came to light after researchers reported it, and no related damage has been reported. Huntress and TechCrunch reported the campaign on August 20, and the impersonating X account has since been flagged. The operation echoes a 2021 campaign attributed to North Korea’s Lazarus Group and underscores continuing risks from counterfeit wallet software following Ledger’s 2020 customer-data breach. The campaign also highlights the need to verify event invitations through official channels, avoid unverified attachments and inspect suspicious documents in isolated environments.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.