Threat Advisory

COLDCARD Phishing Attack Installs Remote Access Tool

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The phishing emails, sent from compliance@, claim a security audit is underway across COLDCARD's hardware cold storage wallet devices. Users are directed to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.

The phishing campaign uses emails impersonating COLDCARD and claims a security audit is underway across its hardware cold storage wallet devices. The emails direct users to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The batch file contains two Base64-encoded files embedded directly in the file. When launched, the script first pretends to perform a diagnostic check on your device but actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The phishing emails, sent from compliance@, claim a security audit is underway across COLDCARD's hardware cold storage wallet devices. Users are directed to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.

The phishing campaign uses emails impersonating COLDCARD and claims a security audit is underway across its hardware cold storage wallet devices. The emails direct users to an alleged 'Security Verification & Incident Reporting Tool,' which downloads a batch file that installs a ConnectWise ScreenConnect installer, giving the threat actor remote access to the device. The batch file contains two Base64-encoded files embedded directly in the file. When launched, the script first pretends to perform a diagnostic check on your device but actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.[emaillocker id="1283"]

The phishing campaign targets users who are concerned about the COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft. The attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware. Security teams should test every layer before attackers do. Threat actors have been using phishing campaigns to trick users into installing remote access tools, which can give them access to sensitive information and systems.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.001 Phishing Spearphishing Attachment
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Command and control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu