Date: 08/24/2026
Severity: High
Summary
A researcher was targeted after Black Hat/DEF CON by a threat actor using X DMs and fake conference planning to build trust. The researcher identified the scam but continued engaging with the actor to study their tactics. The campaign targeted both macOS and Windows users with different malware payloads. The macOS infection delivered AMOS infostealer, while Windows delivered NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy. A malicious Google Apps Script turned a Google Doc into an infection mechanism using ClickFix-style instructions and a manual download option. A second payload disguised as a DocSend installer delivered the appropriate macOS or Windows payload.
Indicators of Compromise (IOC) List
Domains/URLs | apple-googleapi.com GAPIUpdate.dmg apple.eu03hub.com docsend.com/view/evdfym2aj5tend76 docsend.online/download/drivers docsend.web12api.com/api/launcher/start signow.web12api.com/api/launcher/start eu03hub.com/get_file?file=2Ec6QYynajHw eu03hub.com/get_file?file=T3YxekrHsgfaDdXY eu03hub.com/get_file?file=qV06ev1a1pOY msedgewebview1.pro msedgewebview2.pro https://1foqo.lat/core4 microsoft.eu02hub.com https://2fksf.lat/res10.php https://2fksf.lat/res11.php https://3pqow.lat/res12.php |
IP Address | 86.54.25.213 192.253.248.181 87.120.104.88 |
Hash | 8ca79bd95f73a7f984b95e487dc1552b
281f1d9e0638517ac90d61e47fd8be60
6dd77235aaa99153ad790b5e59b49372
f4769ba9e8065727ef26cca72e894f83
cd08e22dbfe032d15b54217f4f4ed350
15afe14b5db2896d35a0c4f3139db85158da120fa90613c975c88f10bbbcc420
|
Github Repository | github.com/ariasalmonterachel13/gapi/releases |
Filepath | /tmp/lksopo /Library/LaunchDaemons/com.xdivcmp.plist |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://2fksf.lat/res11.php" or url like "https://2fksf.lat/res11.php" or siteurl like "https://2fksf.lat/res11.php" or domainname like "apple-googleapi.com" or url like "apple-googleapi.com" or siteurl like "apple-googleapi.com" or domainname like "msedgewebview1.pro" or url like "msedgewebview1.pro" or siteurl like "msedgewebview1.pro" or domainname like "apple.eu03hub.com" or url like "apple.eu03hub.com" or siteurl like "apple.eu03hub.com" or domainname like "https://2fksf.lat/res10.php" or url like "https://2fksf.lat/res10.php" or siteurl like "https://2fksf.lat/res10.php" or domainname like "https://3pqow.lat/res12.php" or url like "https://3pqow.lat/res12.php" or siteurl like "https://3pqow.lat/res12.php" or domainname like "msedgewebview2.pro" or url like "msedgewebview2.pro" or siteurl like "msedgewebview2.pro" or domainname like "microsoft.eu02hub.com" or url like "microsoft.eu02hub.com" or siteurl like "microsoft.eu02hub.com" or domainname like "docsend.com/view/evdfym2aj5tend76" or url like "docsend.com/view/evdfym2aj5tend76" or siteurl like "docsend.com/view/evdfym2aj5tend76" or domainnanme like "docsend.online/download/drivers" or url like "docsend.online/download/drivers" or siteurl like "docsend.online/download/drivers" or domainname like "docsend.web12api.com/api/launcher/start" or url like "docsend.web12api.com/api/launcher/start" or siteurl like "docsend.web12api.com/api/launcher/start" or domainname like "signow.web12api.com/api/launcher/start" or url like "signow.web12api.com/api/launcher/start" or siteurl like "signow.web12api.com/api/launcher/start" or domainname like "eu03hub.com/get_file?file=2Ec6QYynajHw" or url like "eu03hub.com/get_file?file=2Ec6QYynajHw" or siteurl like "eu03hub.com/get_file?file=2Ec6QYynajHw" or domainname like "eu03hub.com/get_file?file=T3YxekrHsgfaDdXY" or url like "eu03hub.com/get_file?file=T3YxekrHsgfaDdXY" or siteurl like "eu03hub.com/get_file?file=T3YxekrHsgfaDdXY" or domainname like "eu03hub.com/get_file?file=qV06ev1a1pOY" or url like "eu03hub.com/get_file?file=qV06ev1a1pOY" or siteurl like "eu03hub.com/get_file?file=qV06ev1a1pOY" or domainname like "https://1foqo.lat/core4" or url like "https://1foqo.lat/core4" or siteurl like "https://1foqo.lat/core4" |
Detection Query 2 : | md5hash IN ("6dd77235aaa99153ad790b5e59b49372","8ca79bd95f73a7f984b95e487dc1552b","f4769ba9e8065727ef26cca72e894f83","281f1d9e0638517ac90d61e47fd8be60","cd08e22dbfe032d15b54217f4f4ed350")
|
Detection Query 3 : | md5hash IN ("6dd77235aaa99153ad790b5e59b49372","8ca79bd95f73a7f984b95e487dc1552b","f4769ba9e8065727ef26cca72e894f83","281f1d9e0638517ac90d61e47fd8be60","cd08e22dbfe032d15b54217f4f4ed350")
|
Detection Query 4 : | sha256hash IN ("15afe14b5db2896d35a0c4f3139db85158da120fa90613c975c88f10bbbcc420")
|
Detection Query 5 : | datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "/tmp/lksopo" or objectname like "/Library/LaunchDaemons/com.xdivcmp.plist") |
Detection Query 6 : | technologygroup = "EDR" and (objectname like "/tmp/lksopo" or objectname like "/Library/LaunchDaemons/com.xdivcmp.plist") |
Reference:
https://www.huntress.com/blog/defcon-phishing-google-doc-malware