Executive Summary
A sophisticated social engineering campaign has been identified leveraging Google Doc sidebars to distribute platform-specific malware. Attackers pose as industry executives on social media (specifically X) to lure victims toward a legitimate Google Doc. The document contains a malicious Google Apps Script that serves as a triage mechanism, identifying the victim's operating system, location, and presence of cryptocurrency wallets before delivering a tailored payload.
Technically, the campaign uses 'ClickFix' lures, where a fake decryption error prompts users to execute terminal commands or download 'manual updates.' macOS users are targeted with variants of the AMOS (Atomic macOS) stealer, while Windows users are infected with a multi-stage PowerShell loader chain. This chain is notable for abusing stolen code-signing certificates from legitimate companies like Discord and Lenovo to bypass security warnings.
This threat is high-impact due to its focus on stealing cryptocurrency credentials and its persistence mechanisms, including a rogue certificate authority (CA) that enables local HTTPS interception. Organizations, particularly those in the financial and technology sectors, should be wary of unsolicited documents and the execution of unverified terminal commands.
