BSIDES BELGRADE 2026
AGENDA 2026
Manufactured Trust
SPEAKERS: Tara Gould
About the Workshop/Talk
Threat actors have been using social engineering techniques for as long as the internet, but technical users are now an especially attractive target because they're more likely to hold cryptocurrency. As a result, threat actors are going to far greater lengths to social engineer their victims. Over the past two years, cybercriminals have been creating fake startup companies complete with professional looking websites, verified social media accounts, merch stores, product roadmaps, employee bios, Github activity, all as an effort to appear legitimate. The fake company then targets victims with the opportunity to earn crypto by testing out a software. The software, available for both Windows and macOS, is packaged to look professional but is actually a low detected stealer that drains the victim's cryptocurrency once installed. This talk will cover several campaigns, breaking down both the social engineering and the technical side of the malware. The goal is to highlight how convincing these operations have become, and why they are so effective even against experienced users.