A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The phishing emails, sent from compliance@, claim a security audit is underway across COLDCARD's hardware cold storage wallet devices. Users are directed to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.
The phishing campaign uses emails impersonating COLDCARD and claims a security audit is underway across its hardware cold storage wallet devices. The emails direct users to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The batch file contains two Base64-encoded files embedded directly in the file. When launched, the script first pretends to perform a diagnostic check on your device but actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.[/subscribe_to_unlock_form]
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The phishing emails, sent from compliance@, claim a security audit is underway across COLDCARD's hardware cold storage wallet devices. Users are directed to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.
The phishing campaign uses emails impersonating COLDCARD and claims a security audit is underway across its hardware cold storage wallet devices. The emails direct users to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The batch file contains two Base64-encoded files embedded directly in the file. When launched, the script first pretends to perform a diagnostic check on your device but actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.[emaillocker id="1283"]
The phishing campaign targets users who are concerned about the COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware. Security teams should test every layer before attackers do. Threat actors have been using phishing campaigns to trick users into installing remote access tools, which can give them access to sensitive information and systems.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.001 | Phishing | Spearphishing Attachment |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
The following reports contain further technical details:
[/emaillocker]