When you target security researchers with malware, getting caught and written up is honestly one of the less unpleasant possible outcomes: https://techcrunch.com/2026/08/20/someone-targeted-security-researchers-using-a-fake-crypto-conference-as-a-lure/
@evacide I can't read the article (because it wants me to disable security protections in my browser), but fake conferences are a TERRIBLE cover for targeting academics. The amount of fake conference spam we routinely get is overwhelming. For an actual conference invite to have any chance of getting my attention, it would have to come from someone I know personally.
@mattblaze The writeup from Huntress Labs is here, in case you're interested in reading it: https://www.huntress.com/blog/defcon-phishing-google-doc-malware
@mattblaze I have made this joke before, but the way to target activists/academics is to offer to cover travel/hotel for the conference.
@evacide That would be a huge red flag!
@mattblaze @evacide The one and only time someone actually invited me to give a keynote presentation, I was very suspicious...