Phishing Campaign Poses as COLDCARD Security Audit to Install Remote Access Tool
A phishing campaign discovered by Proofpoint targeted COLDCARD hardware wallet users with fake security audit emails sent from a spoofed domain, exploiting recent news about the wallet's random number vulnerabilities and an $88.6 million Bitcoin theft. Victims were directed to a fraudulent compliance website and guided by a live chat operator to download a 25.7MB batch file named Coldcard_Diagnostic_Tool.bat from an attacker-controlled GitHub account. The file silently decoded and installed a ConnectWise ScreenConnect remote access client using certutil and PowerShell, while displaying a decoy DocuSign printer driver screen to mask the infection. Once installed, ScreenConnect connected to an attacker-controlled server, granting full remote access to the victim's Windows device. The campaign was designed to bypass suspicion by assuring users that no recovery seed phrases were required, and live chat agents coached victims through UAC elevation prompts in real time.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in