Cardano Wallet Users Beware: Carefully Disguised Phishing Attacks Surface

robot
Abstract generation in progress

Source: Cryptonews Original Title: Cardano wallets under threat? suspicious phishing campaign surfaces Original Link: https://crypto.news/cardano-wallets-under-threat-phishing-campaign/

Malicious Installer Contains Remote Access Trojan

Cardano users are becoming targets of a phishing campaign where attackers promote the fraudulent Eternl Desktop application download through fake emails.

The attack leverages professionally crafted email messages referencing NIGHT and ATMA token rewards and the Diffusion Staking Basket program to establish credibility. Threat hunter Anurag discovered a malicious installer distributed via newly registered domains.

The 23.3MB Eternl.msi file contains a hidden remote management tool that establishes unauthorized access to the victim’s system without their knowledge.

The malicious MSI installer carries and executes a file named unattended-updater.exe. When run, this executable creates a folder structure under the system’s Program Files directory.

The installer writes multiple configuration files, including unattended.json, logger.json, mandatory.json, and pc.json. The unattended.json configuration enables remote access features without user interaction.

Network analysis shows the malware connecting to remote management infrastructure. The executable uses hardcoded API credentials to transmit system event information in JSON format to a remote server.

Security researchers classify this behavior as a critical threat. The remote management tool provides threat actors with persistent access, remote command execution, and credential theft capabilities.

Activities Targeting Cardano Users

Phishing emails maintain a sophisticated, professional tone, with correct grammar and no spelling errors. The fraudulent announcement creates a nearly identical copy of the official Eternl Desktop release, including messages about hardware wallet compatibility, local key management, and advanced delegation controls.

Attackers exploit cryptocurrency governance narratives and ecosystem-specific references to distribute covert access tools. References to NIGHT and ATMA token rewards add false legitimacy to the malicious activity.

Cardano users seeking to participate in staking or governance functions face high risks from social engineering tactics that mimic legitimate ecosystem developments.

The installer is distributed via newly registered domains without official verification or digital signature validation.

Security Recommendations

Users should verify the authenticity of wallet applications only through official channels before downloading.

Anurag’s malware analysis reveals supply chain abuse attempts aimed at establishing persistent unauthorized access. The remote management tool gives attackers remote control capabilities, jeopardizing wallet security and private key access.

Users should avoid downloading wallet applications from unverified sources or newly registered domains, regardless of how polished or professional the email appearance may be.

ADA-2,63%
NIGHT-4,16%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 8
  • Repost
  • Share
Comment
0/400
SignatureAnxietyvip
· 01-05 12:02
Another phishing... Cardano users have been having a tough time lately, gotta keep a close eye on the Eternl wallet.
View OriginalReply0
SatsStackingvip
· 01-05 11:17
Fishing again? These people are really idle... Wallet security still depends on yourself, everyone.
View OriginalReply0
FreeRidervip
· 01-03 19:50
Here we go again? I've been on guard against Eternl phishing for a while, the key is to educate those newbies.
View OriginalReply0
GhostAddressHuntervip
· 01-03 19:50
Coming again? The Cardano ecosystem has been really frequently targeted by phishing in the past two years... I keep telling people not to click on links in emails, but many don't listen.
View OriginalReply0
PonziDetectorvip
· 01-03 19:50
Another phishing attempt? Why does Cardano keep getting targeted... Be careful of fake emails, everyone.
View OriginalReply0
MrDecodervip
· 01-03 19:32
Fishing again, this time targeting Cardano... Really need to be more cautious, don't click on unfamiliar links.
View OriginalReply0
TooScaredToSellvip
· 01-03 19:21
Really? Eternl can also be copied? These people are getting more and more desperate... Quickly check your wallet address.
View OriginalReply0
CryptoHistoryClassvip
· 01-03 19:20
ah, classic phishing playbook—same moves as the mt. gox era, just different wallet names. investors never learn pattern recognition, do they? this is what happens when adoption outpaces security literacy. statistically speaking, we're hitting that peak delusion phase where everyone's downloading random wallets. history's rhyming again, and most won't notice till their keys are gone.
Reply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)