A phishing campaign is abusing fears around the COLDCARD wallet vulnerability and the suspected $88.6 million Bitcoin theft to lure victims into installing ScreenConnect remote access software. The attackers impersonate COLDCARD with fake security audit emails and a bogus support site to pressure users into running a malicious diagnostic tool. #COLDCARD #ScreenConnect #Coldcard_Diagnostic_Tool #activeretirementrelocation.com
Keypoints
- Proofpoint uncovered a phishing campaign impersonating COLDCARD.
- The emails claim a security audit is underway across hardware wallet devices.
- The lure exploits concern over an alleged COLDCARD-related Bitcoin theft.
- Victims are prompted to download a fake diagnostic tool that installs ScreenConnect.
- The attackers use a fake support chat to pressure users into granting access.