Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label COLDCARD wallet vulnerability. Show all posts

Phishing Campaign Exploits COLDCARD Vulnerability Fears to Spread ScreenConnect

 

A new phishing campaign is taking advantage of concerns over a recently revealed COLDCARD wallet vulnerability and the suspected theft of $88.6 million in Bitcoin to trick cryptocurrency users into installing remote-access software.

Cybersecurity firm Proofpoint, which identified the campaign, said attackers are sending emails that impersonate COLDCARD and falsely claim that a security audit is being conducted across its hardware cold-storage wallets.

The campaign follows the reported theft of around 1,367 Bitcoin, estimated to be worth $88.6 million, from 4,585 addresses. The incident is believed to have been linked to a random number generation flaw affecting several COLDCARD models and firmware versions.

The fraudulent emails originate from compliance@coldcardteamnews.com and carry the subject line "Hardware audit now available." Recipients are told that recent security findings have prompted COLDCARD to verify devices across different hardware revisions.

"We are writing to inform you of a coordinated security audit now underway across the COLDCARD device network. Recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed," reads the fake security audit emails.

The messages direct recipients to a supposed "Security Verification & Incident Reporting Tool." The attackers claim that the process is air-gapped, does not require users to provide their recovery seed and must be completed by August 10.

Clicking the "Access the Audit Tool" button takes users to coldcardcompliance.com, a fraudulent website designed to resemble COLDCARD. Visitors are then prompted to click "Start Hardware Audit" to download the alleged diagnostic tool.

The site also features a live "Customer Service" chat function, which is presented as a way for users to receive assistance with their COLDCARD devices.

According to conversations reviewed by Proofpoint, an operator asks victims whether they are using Windows or macOS before providing further instructions. Windows users are told to execute the downloaded file. When one victim reported seeing a black command window and an administrator prompt, the operator claimed the prompt was necessary to begin installation and instructed the user to select "Yes."

Proofpoint suspects that the chat interactions are being conducted by human operators rather than an automated system. This would allow the attackers to address victims' concerns directly and persuade hesitant users to continue with the installation.

Fake diagnostic tool installs ScreenConnect

Proofpoint said clicking "Start Hardware Audit" downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account.

An analysis by BleepingComputer found that the 25.7MB batch file contains two Base64-encoded files embedded within it.

When executed, the script initially appears to run a diagnostic check. In reality, it determines whether the victim has administrator privileges. If elevated access is unavailable, it uses PowerShell to restart itself and trigger a User Account Control prompt.

The script subsequently extracts the embedded files into a randomly generated directory inside the Windows temporary folder. The files are saved as setup.msi and docusign.exe before being decoded using Windows certutil.

After installing setup.msi, the script launches docusign.exe, displays an "Installation Complete" message and removes the temporary directory. The executable is a legitimate, digitally signed program associated with a DocuSign printer driver and serves as a distraction from the malicious activity.

The setup.msi package, however, installs ConnectWise ScreenConnect, a remote-management application that can provide attackers with access to the compromised computer.

Proofpoint said the malicious installation connects to activeretirementrelocation[.]com, which serves as the ScreenConnect command-and-control server operated by the attackers.

Once a connection is established, threat actors could potentially control the affected computer remotely, steal sensitive information or cryptocurrency, and deploy additional malicious software. Proofpoint also warned that the compromised access could ultimately be leveraged to deploy ransomware.