
Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT
A targeted fake-job campaign compromised a cryptocurrency organization after an employee was approached through LinkedIn while changing jobs. The attacker posed as a recruiter for a fictitious Web3 protocol, arranged interviews through Calendly, and sent a technical assessment disguised as a Google Sheet. The assessment page was hosted through Google Apps Script and used genuine […]
The post Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT appeared first on Cyber Security News.