Urgent.News

What's breaking now, across thousands of outlets.

Tech

COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It

COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It 1. Basic Information Article Title : COLDCARD security audit phishing attack installs remote access tool Publisher : BleepingComputer Publication Date : August 5, 2026 Original Source : BleepingComputer Related Information Source : Proofpoint (campaign discovery and IOC sharing) Related…

On August 5, 2026, security experts warned of a sophisticated phishing attack targeting users of COLDCARD hardware wallets. The attackers sent emails pretending to be from the COLDCARD team, urging users to perform a security audit. The email claimed urgent attention was needed for hardware revisions, with a deadline of August 10. It linked to a fraudulent website (coldcardcompliance.com) and claimed the audit process would be "air-gapped" and would not request recovery seeds.

The email contained a link to a 25.7MB batch file named Coldcard_Diagnostic_Tool.bat, hosted on an attacker-controlled GitHub repository. When the user downloaded the file, it displayed a fake diagnostic screen and checked for administrator privileges. If the user did not have admin rights, the script would elevate itself using PowerShell, requesting a User Account Control (UAC) prompt.

The batch file contained embedded Base64 data, which was decoded using the certutil command. The decoded installer, setup.msi, was used to install a ScreenConnect Remote Access Management (RMM) tool. Separately, the batch file also installed a decoy DocuSign printer driver, using the signed docusign.exe file to create the illusion of legitimacy.

Once installed, ScreenConnect allowed the attackers to gain remote control of the victim's device, appearing as the authorized user. The attackers could then search through wallets, credentials, and data, deploy additional malware, or even deploy ransomware under certain conditions. Although the article does not confirm specific damage, the threat posed by this multi-layered attack was deemed high.

To successfully execute the attack, the victim had to trust the fear-inducing language in the initial email, click through to the malicious website, download and run the batch file, and approve the UAC prompt. Should any of these steps fail, the attacker's plan would be thwarted. However, due to the use of a legitimate RMM tool and a signed decoy driver, the attack remained undetected by many security measures, highlighting the importance of ongoing vigilance and awareness in combating such sophisticated phishing schemes.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Thursday 6 August →