Attackers impersonated a CoinDesk executive on X to lure cybersecurity researchers with fake conference invites via Google Docs. The campaign deployed AMOS stealer on macOS and NetSupport RAT on Windows, exploiting ClickFix techniques and trusted platforms. Huntress and TechCrunch exposed the operation amid $17B in 2025 crypto scam losses.