Malicious Google Docs Weaponized as Interactive Installers
Adversaries have ingeniously manipulated Google Docs to perform a function utterly unexpected from a cloud-based word processor: they transformed a standard document into an interactive malware installation vector. Following the conclusion of the prestigious Black Hat and DEF CON security conferences, a malicious actor initiated contact with various attendees via the X platform. Impersonating a senior executive from CoinDesk, the attacker proposed a discussion regarding an upcoming online conference. However, instead of a conventional file, the victim received a deeply compromised Google Document featuring a bespoke sidebar and demanding a fictitious “decryption key.”
The Mechanics of the ClickFix Evolution
The document embedded malicious Google Apps Script that actively rendered a fabricated DecryptPanel.html interface. This script covertly harvested system information, exfiltrated user activity data via Telegram, and meticulously determined whether the target operated a Windows or macOS environment. Deliberately, any entered decryption key failed, prompting the document to helpfully offer to “fix the decryption.” This deceptive maneuver effectively transplanted the notorious ClickFix scheme directly into the seemingly secure confines of Google Docs.
Targeting macOS with AMOS Stealer
On macOS systems, the fabricated prompt instructed the victim to execute a specific command within the terminal or download a “manual update” directly from GitHub. Selecting the latter option delivered the devastating AMOS stealer. This malware aggressively plunders browser passwords, persistent cookies, Keychain data, cryptocurrency wallet files, and localized Telegram data. Furthermore, the malware explicitly requested access to personal notes before establishing a resilient backdoor via a dedicated LaunchDaemon, ultimately possessing the capability to subjugate the infected Mac into a clandestine SOCKS5 proxy.
Assaulting Windows with ClickOnce
Conversely, the fraudulent decryption process on Windows systems demanded an update for an entirely fabricated “Google API Connector.” Activating the provided button launched a malicious ClickOnce installer. To further obfuscate the infection, a highly convincing, though utterly fraudulent, Google Workspace Marketplace interface materialized on the screen. An alternative attack vector suggested pasting a provided PowerShell command, which subsequently downloaded supplementary malicious components. The systematic abuse of Google Apps Script has featured prominently in prior attacks, primarily because requests directed toward legitimate Google infrastructure effortlessly disappear within the vast ocean of normal network traffic.
Secondary Attack Vectors and Rogue Proxies
When the initial lure failed to compromise the target, the persistent attacker swiftly delivered a secondary document masquerading as a secure Dropbox DocSend link. This counterfeit installer intelligently identified the operating platform, harvested detailed computer specifications, and stealthily loaded the subsequent attack stage directly into system memory. On Windows machines, this sophisticated chain delivered three distinct payloads simultaneously: the NetSupport Remote Access Trojan (RAT) for absolute administrative control, a localized proxy equipped with a rogue root certificate, and a specialized implant designed specifically to target Ledger cryptocurrency wallets.
The localized proxy proved to be the most extraordinary component of the attack. The malware audaciously injected its own rogue certificate authority, deceptively named “Google Trust Services,” directly into the Windows operating system. It then systematically redirected all queries destined for VirusTotal back to localhost, enabling the attacker to present entirely fabricated, clean scan results without triggering any browser certificate warnings. Alarmingly, even after the partial removal of the malicious components, the rogue root certificate, the manipulated hosts file entry, and the compromised firewall rules could persistently remain entrenched within the system.
Infrastructure and Ongoing Threats
In their comprehensive analysis of the DEF CON phishing campaign, Huntress emphatically highlights that the discovered infrastructure was clearly designed for sustained, widespread operations rather than a singular, isolated attack. The exact same malicious loader proliferated under numerous deceptive brand names, while the command and control servers utilized a highly predictable, repetitive naming convention. A vigilant Huntress employee accurately identified the initial lure and deliberately sustained the correspondence specifically to analyze the entire exploitation chain.
Legitimate Google services increasingly function not merely as deceptive lures, but as integral components of the malicious infrastructure itself. Recently, specialists at Talos dissected a separate, complex campaign where attackers transplanted critical attack components directly into Google Docs and Sheets, rapidly replacing blocked documents with fresh, malicious iterations.
Huntress has previously encountered this deliberate exploitation of implicit user trust. In a separate campaign, an ostensibly routine invoice originating from an accounting department manipulated an employee into manually initiating an execution chain. This chain subsequently installed entirely legitimate remote administration tools, rather than relying upon a conventional, easily detected malicious file.
Malicious actors continue to aggressively exploit the inherent trust associated with official Google domains. During the spring of 2026, the sophisticated GTFire campaign successfully concealed malicious phishing redirects behind legitimate Google services, expertly manipulating suspicious URLs to appear completely benign to both the end-user and automated security systems.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.