A threat actor operating under the X handle @HartmansDoeke impersonated CoinDesk’s vice president to approach cybersecurity researchers with a fake online cryptocurrency conference. The campaign, documented by researchers at Huntress, used a booby-trapped Google Doc with a Google Apps Script designed to collect host information and deliver platform-specific malware. For macOS systems, the malware was the Atomic macOS Stealer (AMOS), an infostealer capable of harvesting passwords, browser cookies, and cryptocurrency wallet credentials. For Windows systems, the attacker deployed the NetSupport RAT along with a fake Ledger installer. Huntress and TechCrunch publicly reported the campaign on August 20, 2026, roughly eleven days after the initial outreach began.
Source: Read the original article

