TLDR Hackers are targeting Cardano users by impersonating the Eternl Desktop wallet team through phishing emails. The phishing emails promote a fake wallet downloadTLDR Hackers are targeting Cardano users by impersonating the Eternl Desktop wallet team through phishing emails. The phishing emails promote a fake wallet download

New Cardano Phishing Scam Uses Fake Wallet to Spread Malware

TLDR

  • Hackers are targeting Cardano users by impersonating the Eternl Desktop wallet team through phishing emails.
  • The phishing emails promote a fake wallet download that claims to offer crypto rewards like NIGHT and ATMA tokens.
  • Victims are redirected to a newly registered domain that delivers a malicious MSI installer package.
  • The installer secretly includes a remote access tool called LogMeIn Resolve, which enables full system control.
  • Once installed, the malware creates system directories and configuration files that allow remote access without user permission.

Cardano users face a new security threat as cybercriminals impersonate the Eternl Desktop wallet team, distributing malware via phishing emails, creating urgency using fake crypto rewards, and deploying remote access tools to gain full system control through a fake installer package.

Fake Eternl Wallet Website Spreads Malware Through Polished Emails

Attackers are impersonating the Eternl team by sending emails promoting a fake desktop wallet. These messages claim to support Cardano staking and governance.

The emails highlight false benefits, such as NIGHT and ATMA token rewards, to attract attention and encourage clicks. Users are redirected to a malicious domain: download(dot)eternldesktop(dot)network.

According to threat researcher Anurag, the attackers copied the original Eternl Desktop announcement. They added fake features such as local key management and hardware wallet compatibility.

Each email uses professional language without spelling mistakes, making the scam appear genuine. The emails include a fake download link to a harmful MSI installer.

Once installed, the file deploys malware designed to allow hackers remote access. The file bypasses standard verification and lacks digital signature validation.

Malicious Installer Contains Hidden Remote Access Tool

The installer, named Eternl.msi, has a file hash of 8fa4844e40669c1cb417d7cf923bf3e0. It contains a bundled LogMeIn Resolve tool.

When executed, it drops an executable titled unattended updater.exe. The original filename is GoToResolveUnattendedUpdater.exe.

The executable builds a folder structure in Program Files. It then writes multiple configuration files, such as unattended.json and pc.json.

The unattended.json file activates remote access without the user’s consent. It enables full system control without requiring interaction.

Network analysis confirms the executable connects to known GoTo Resolve domains. These include devices-iot.console.gotoresolve.com and dumpster.console.gotoresolve.com.

The malware sends system data in JSON format. It establishes a remote connection to accept hacker commands.

Fake Crypto Campaign Mimics Past Meta Ad Scam

This Cardano phishing attack mirrors an earlier scam targeting Meta business users. Victims received emails about ad account violations.

The attackers claimed the accounts were suspended due to EU regulation breaches. They used Instagram branding and official language.

Clicking the link took users to a fake Meta Business page. The page warned of account termination if no action was taken.

Users were prompted to input credentials. A fake support chat walked them through restoring their accounts.

Researchers urge users to verify wallet downloads from trusted sources only. Newly registered domains pose a high risk.

Security experts warn that even polished emails can contain hidden threats. Official websites remain the safest option for wallet software.

The post New Cardano Phishing Scam Uses Fake Wallet to Spread Malware appeared first on CoinCentral.

Market Opportunity
Scamcoin Logo
Scamcoin Price(SCAM)
$0.001071
$0.001071$0.001071
0.00%
USD
Scamcoin (SCAM) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Puregold’s ‘Pusong Panalo’ brightens students’ path in remote Rizal village

Puregold’s ‘Pusong Panalo’ brightens students’ path in remote Rizal village

In an upland village in Tanay, Rizal, children would trek for up to one hour before sunrise just to make it to class. Many from poor and indigenous families, these
Share
Bworldonline2026/01/09 14:10
House of Doge Acquires Stake in Italian Football Club, Boosting Dogecoin’s Real-World Ties

House of Doge Acquires Stake in Italian Football Club, Boosting Dogecoin’s Real-World Ties

The post House of Doge Acquires Stake in Italian Football Club, Boosting Dogecoin’s Real-World Ties appeared on BitcoinEthereumNews.com. COINOTAG recommends • Exchange signup 💹 Trade with pro tools Fast execution, robust charts, clean risk controls. 👉 Open account → COINOTAG recommends • Exchange signup 🚀 Smooth orders, clear control Advanced order types and market depth in one view. 👉 Create account → COINOTAG recommends • Exchange signup 📈 Clarity in volatile markets Plan entries & exits, manage positions with discipline. 👉 Sign up → COINOTAG recommends • Exchange signup ⚡ Speed, depth, reliability Execute confidently when timing matters. 👉 Open account → COINOTAG recommends • Exchange signup 🧭 A focused workflow for traders Alerts, watchlists, and a repeatable process. 👉 Get started → COINOTAG recommends • Exchange signup ✅ Data‑driven decisions Focus on process—not noise. 👉 Sign up → House of Doge, the corporate arm of the Dogecoin Foundation, has acquired a majority stake in U.S. Triestina Calcio 1918, marking the first time a cryptocurrency company owns a European football club. This partnership with Brag House Holdings injects capital for operations and introduces crypto payments for fans. Landmark Acquisition: House of Doge secures majority ownership in Italy’s historic Triestina club, blending crypto with sports. Capital Injection: New funds will enhance team operations, community programs, and fan experiences through blockchain integration. Strategic Merger: Ties into a $50 million Nasdaq merger with Brag House, expanding Dogecoin’s ecosystem into real-world assets with a projected growth in user engagement by 30% based on similar crypto-sports ventures. Discover how House of Doge’s acquisition of Triestina Calcio revolutionizes crypto in football. Explore the impact on Dogecoin community and real-world assets. Read now for insights on this groundbreaking deal! What is the House of Doge Acquisition of U.S. Triestina Calcio 1918? House of Doge acquisition of U.S. Triestina Calcio 1918 represents a pioneering move where the Dogecoin Foundation’s corporate entity gains majority control of one…
Share
BitcoinEthereumNews2025/10/21 06:40
Shiba Inu Price Forecast: Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

Shiba Inu Price Forecast: Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale

While Shiba Inu (SHIB) continues to build its ecosystem and PEPE holds onto its viral roots, a new contender, Layer […] The post Shiba Inu Price Forecast: Why This New Trending Meme Coin Is Being Dubbed The New PEPE After Record Presale appeared first on Coindoo.
Share
Coindoo2025/09/18 01:13