A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download. The attack leverages professionallyA phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download. The attack leverages professionally

Cardano wallets under threat? suspicious phishing campaign surfaces

A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download.

The attack leverages professionally crafted messages referencing NIGHT and ATMA token rewards through the Diffusion Staking Basket program to establish credibility.

Threat hunter Anurag identified a malicious installer distributed through a newly registered domain, download.eternldesktop.network.

The 23.3 megabyte Eternl.msi file contains a hidden LogMeIn Resolve remote management tool that establishes unauthorized access to victim systems without user awareness.

Fake installer bundles remote access trojan

The malicious MSI installer carries a specific and drops an executable called unattended-updater.exe with the original filename. During runtime, the executable creates a folder structure under the system’s Program Files directory.

The installer writes multiple configuration files including unattended.json, logger.json, mandatory.json, and pc.json.

The unattended.json configuration enables remote access functionality without requiring user interaction.

Network analysis reveals the malware connects to GoTo Resolve infrastructure. The executable transmits system event information in JSON format to remote servers using hardcoded API credentials.

Security researchers classify the behavior as critical. Remote management tools provide threat actors with capabilities for long-term persistence, remote command execution, and credential harvesting once installed on victim systems.

The phishing emails maintain a polished, professional tone with proper grammar and no spelling errors.

The fraudulent announcement creates a nearly identical replica of the official Eternl Desktop release, complete with messaging about hardware wallet compatibility, local key management, and advanced delegation controls.

Campaign targets Cardano users

The attackers weaponize cryptocurrency governance narratives and ecosystem-specific references to distribute covert access tools.

References to NIGHT and ATMA token rewards through the Diffusion Staking Basket program lend false legitimacy to the malicious campaign.

Cardano users seeking to participate in staking or governance features face high risk from social engineering tactics that mimic legitimate ecosystem developments.

The newly registered domain distributes the installer without official verification or digital signature validation.

Users should verify software authenticity exclusively through official channels before downloading wallet applications.

Anurag’s malware analysis revealed the supply-chain abuse attempt aimed at establishing persistent unauthorized access.

The GoTo Resolve tool provides attackers with remote control capabilities that compromise wallet security and private key access.

Users should avoid downloading wallet applications from unverified sources or newly registered domains regardless of email polish or professional appearance.

Market Opportunity
Midnight Logo
Midnight Price(NIGHT)
$0.07084
$0.07084$0.07084
-0.97%
USD
Midnight (NIGHT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Stellar (XLM) Eyes $0.28 After Roadmap Signals Stablecoin and Lending Growth

Stellar (XLM) Eyes $0.28 After Roadmap Signals Stablecoin and Lending Growth

Stellar (XLM) is taking major steps in the world of DeFi with its new Q1 2026 roadmap that has been rolled out. This new roadmap is focused on the upcoming mainnet
Share
Tronweekly2026/01/12 03:30
X Smart Cashtags: Elon Musk’s Platform Eyes Crypto and Stock Trading Integration

X Smart Cashtags: Elon Musk’s Platform Eyes Crypto and Stock Trading Integration

A newly teased feature called Smart Cashtags, revealed by X’s head of product Nikita Bier, suggests the platform is moving beyond passive market commentary toward
Share
Coinstats2026/01/12 02:18
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36