Cybercriminals are exploiting the news of the #COLDCARD hardware wallet vulnerability in phishing attacks to install malware.
A reported flaw in COLDCARD firmware has led to the theft of tens of millions worth of Bitcoin.
Now, Proofpoint has observed social engineering leveraging “hardware audit” themes impersonating COLDCARD in email-based phishing campaigns.
Emails impersonate COLDCARD and purport to highlight a security audit relating to the incident. Messages contain a URL that leads to a site impersonating COLDCARD with a “Start Hardware Audit” button.
If clicked, the button leads to a BAT file hosted on GitHub, which drops an MSI file and ultimately installs ScreenConnect. This can lead to data or financial theft, or to the installation of follow-on malware such as ransomware.
IOCs:
• Sender email - compliance@coldcardteamnews[.]com
• Fake site – coldcardcompliance[.]com
• Payload - hxxps://github[.]com/newallyson/ColdCard/releases/download/5.7/Coldcard_Diagnostic_Tool.bat
• ScreenConnect C2 - activeretirementrelocation[.]com