Cybercriminals are leveraging the recent $88.6 million Bitcoin theft panic to trick COLDCARD users into installing ScreenConnect remote access software via fake security audits.
Key Takeaways
- Attackers are impersonating COLDCARD via fake 'security audit' emails.
- The goal is to install ConnectWise ScreenConnect for remote device control.
- The campaign exploits psychological fear following a massive $88.6M Bitcoin theft.
- Real human operators are used in fake chats to manipulate victims.
A sophisticated phishing campaign is currently targeting COLDCARD hardware wallet users, masquerading as a mandatory security audit. Following the recent disclosure of a vulnerability that led to an estimated $88.6 million Bitcoin theft, attackers are capitalizing on user anxiety to deploy malicious remote access software.
According to research by Proofpoint, the attackers use emails from domains like [email protected] with the subject 'Hardware audit now available.' These emails direct users to a fraudulent website, coldcardcompliance.com, which mimics the legitimate COLDCARD interface to build trust. Once users click the 'Start Hardware Audit' button, they are prompted to download a malicious batch file.
Why This Matters
BozokMedia analysis shows that this is not a standard automated bot attack. The attackers are employing real human operators in a live chat feature on the phishing site. These operators guide victims through the installation process, even convincing them to bypass Windows User Account Control (UAC) prompts by claiming it is part of the 'diagnostic' process. This level of human interaction makes the scam significantly more convincing and dangerous.
The convergence of technical exploits and high-pressure social engineering represents the new frontier of targeted cryptocurrency theft.
The technical payload is particularly deceptive. The downloaded script executes a batch file that installs a legitimate-looking DocuSign printer driver as a decoy. However, the primary payload is a ConnectWise ScreenConnect installer. Once active, this tool grants the threat actor full remote access to the victim's computer, enabling them to steal private keys, drain wallets, or deploy ransomware.
Historical Background
The backdrop of this attack is a significant security flaw in COLDCARD's random number generation (RNG) across multiple models. This flaw was linked to the theft of approximately 1,367 Bitcoin from thousands of addresses, creating a climate of fear that hackers are now expertly weaponizing.
Frequently Asked Questions
1. How can I identify a fake COLDCARD email?
Official communications will never pressure you to download a 'diagnostic tool' via a link in an email. Always verify through official channels.
2. What should I do if I have already installed the tool?
Immediately disconnect your device from the internet, use a different clean device to move your funds, and perform a full system wipe.