A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download. The attack leverages professionallyA phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download. The attack leverages professionally

Cardano wallets under threat? suspicious phishing campaign surfaces

A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download.

The attack leverages professionally crafted messages referencing NIGHT and ATMA token rewards through the Diffusion Staking Basket program to establish credibility.

Threat hunter Anurag identified a malicious installer distributed through a newly registered domain, download.eternldesktop.network.

The 23.3 megabyte Eternl.msi file contains a hidden LogMeIn Resolve remote management tool that establishes unauthorized access to victim systems without user awareness.

Fake installer bundles remote access trojan

The malicious MSI installer carries a specific and drops an executable called unattended-updater.exe with the original filename. During runtime, the executable creates a folder structure under the system’s Program Files directory.

The installer writes multiple configuration files including unattended.json, logger.json, mandatory.json, and pc.json.

The unattended.json configuration enables remote access functionality without requiring user interaction.

Network analysis reveals the malware connects to GoTo Resolve infrastructure. The executable transmits system event information in JSON format to remote servers using hardcoded API credentials.

Security researchers classify the behavior as critical. Remote management tools provide threat actors with capabilities for long-term persistence, remote command execution, and credential harvesting once installed on victim systems.

The phishing emails maintain a polished, professional tone with proper grammar and no spelling errors.

The fraudulent announcement creates a nearly identical replica of the official Eternl Desktop release, complete with messaging about hardware wallet compatibility, local key management, and advanced delegation controls.

Campaign targets Cardano users

The attackers weaponize cryptocurrency governance narratives and ecosystem-specific references to distribute covert access tools.

References to NIGHT and ATMA token rewards through the Diffusion Staking Basket program lend false legitimacy to the malicious campaign.

Cardano users seeking to participate in staking or governance features face high risk from social engineering tactics that mimic legitimate ecosystem developments.

The newly registered domain distributes the installer without official verification or digital signature validation.

Users should verify software authenticity exclusively through official channels before downloading wallet applications.

Anurag’s malware analysis revealed the supply-chain abuse attempt aimed at establishing persistent unauthorized access.

The GoTo Resolve tool provides attackers with remote control capabilities that compromise wallet security and private key access.

Users should avoid downloading wallet applications from unverified sources or newly registered domains regardless of email polish or professional appearance.

Market Opportunity
Midnight Logo
Midnight Price(NIGHT)
$0.0779
$0.0779$0.0779
+0.28%
USD
Midnight (NIGHT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Price if Ripple Becomes a Fully Regulated and Operational National Bank

XRP Price if Ripple Becomes a Fully Regulated and Operational National Bank

Ripple's plan to become a fully regulated national bank has reached an advanced stage, leading to discussions about how it could impact the XRP price. Recently,
Share
Coinstats2026/01/07 13:38
Romania scales back digital IDs as Costa Rica unveils new app

Romania scales back digital IDs as Costa Rica unveils new app

The post Romania scales back digital IDs as Costa Rica unveils new app appeared on BitcoinEthereumNews.com. Homepage > News > Business > Romania scales back digital IDs as Costa Rica unveils new app Romanian authorities have announced plans to reduce the number of digital identity cards previously intended for free distribution amid the European nation’s fiscal crisis. Romania will reduce the distribution of free digital IDs from 5 million to 3.5 million. The move follows a budget cut of $24.6 million from the original $82 million earmarked for the ambitious digitization project, with the Ministry of Interior aiming to “streamline the use of funds.” Under the memorandum published by the ministry, authorities disclosed that the budget cuts are justifiable in the face of the country’s “systemic fiscal risk.” They added that the move stems from low public interest in receiving the free digital ID. Early in the year, Romania began issuing digital IDs to citizens with support from the European Union’s Recovery and Resilience Plan (PNRR). Details of the agreement stated that Romania will have to issue five million digital IDs to its citizens for free before June 2026, a milestone unlikely to be met following the budget cuts. Since launch, the country has issued a total of 436,674 digital IDs to citizens, a far cry from its original targets. Apart from distributing free digital IDs, Romania is expected to develop and roll out 11 online public services and launch a national awareness campaign. However, only four of the 11 online public services have been completed, with the remaining seven still in the works, with no clear date for mainstream launch. Following the delays, Romania may face a €264 million ($310 million) penalty from the European Commission if it fails to meet its digital ID targets. Industry experts say the fine may exacerbate the current fiscal crisis faced by the country while the government mulls solutions…
Share
BitcoinEthereumNews2025/09/23 11:03
The Shocking Transparency Gap In South Korea’s Digital Currency Strategy

The Shocking Transparency Gap In South Korea’s Digital Currency Strategy

The post The Shocking Transparency Gap In South Korea’s Digital Currency Strategy appeared on BitcoinEthereumNews.com. Bank Of Korea Stablecoin Data: The Shocking
Share
BitcoinEthereumNews2026/01/07 14:11