CYBERSECURITYTRACKER
TRACKING4,538 stories855 vuln stories
Permanent story citation

Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4955

As cited

Citation snapshot as of .

threat intel

Post-DEF CON Phishing Uses Google Doc Apps Script to Deliver Malware

A Huntress researcher identified a phishing campaign active after Black Hat and DEF CON that leverages X (Twitter) direct messages and malicious documents containing Google Docs Apps Script to distribute AMOS, NetSupport RAT, and other malware payloads. The campaign targets security professionals and conference attendees through social engineering.

Why it matters: Security professionals and conference attendees are at immediate risk from social engineering via X DMs and crafted documents; defenders should scrutinize suspicious document links and review X account security for compromise indicators.

Source published
First seen by Cybersecurity Tracker

Source attribution