The post Fake emails target Cardano users with remote access malware appeared on BitcoinEthereumNews.com. A phishing campaign is targeting Cardano users throughThe post Fake emails target Cardano users with remote access malware appeared on BitcoinEthereumNews.com. A phishing campaign is targeting Cardano users through

Fake emails target Cardano users with remote access malware

2026/01/04 01:33
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download.

The attack leverages professionally crafted messages referencing NIGHT and ATMA token rewards through the Diffusion Staking Basket program to establish credibility.

Threat hunter Anurag identified a malicious installer distributed through a newly registered domain, download.eternldesktop.network.

The 23.3 megabyte Eternl.msi file contains a hidden LogMeIn Resolve remote management tool that establishes unauthorized access to victim systems without user awareness.

Fake installer bundles remote access trojan

The malicious MSI installer carries a specific and drops an executable called unattended-updater.exe with the original filename. During runtime, the executable creates a folder structure under the system’s Program Files directory.

The installer writes multiple configuration files including unattended.json, logger.json, mandatory.json, and pc.json.

The unattended.json configuration enables remote access functionality without requiring user interaction.

Network analysis reveals the malware connects to GoTo Resolve infrastructure. The executable transmits system event information in JSON format to remote servers using hardcoded API credentials.

Security researchers classify the behavior as critical. Remote management tools provide threat actors with capabilities for long-term persistence, remote command execution, and credential harvesting once installed on victim systems.

The phishing emails maintain a polished, professional tone with proper grammar and no spelling errors.

The fraudulent announcement creates a nearly identical replica of the official Eternl Desktop release, complete with messaging about hardware wallet compatibility, local key management, and advanced delegation controls.

Campaign targets Cardano users

The attackers weaponize cryptocurrency governance narratives and ecosystem-specific references to distribute covert access tools.

References to NIGHT and ATMA token rewards through the Diffusion Staking Basket program lend false legitimacy to the malicious campaign.

Cardano users seeking to participate in staking or governance features face high risk from social engineering tactics that mimic legitimate ecosystem developments.

The newly registered domain distributes the installer without official verification or digital signature validation.

Users should verify software authenticity exclusively through official channels before downloading wallet applications.

Anurag’s malware analysis revealed the supply-chain abuse attempt aimed at establishing persistent unauthorized access.

The GoTo Resolve tool provides attackers with remote control capabilities that compromise wallet security and private key access.

Users should avoid downloading wallet applications from unverified sources or newly registered domains regardless of email polish or professional appearance.

Source: https://crypto.news/cardano-wallets-under-threat-phishing-campaign/

시장 기회
Midnight 로고
Midnight 가격(NIGHT)
$0.04073
$0.04073$0.04073
-1.02%
USD
Midnight (NIGHT) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!