Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement
A phishing campaign targeting Cardano users has been identified, posing risks to those attempting to download the Eternl Desktop application. The attack uses a deceptive email that mimics a legitimate wallet solution for Cardano token staking and…
A phishing campaign targeting Cardano users has been identified, posing risks to those attempting to download the Eternl Desktop application. The attack uses a deceptive email that mimics a legitimate wallet solution for Cardano token staking and governance participation.
The fraudulent communication mentions ecosystem incentives, such as NIGHT and ATMA token rewards through the Diffusion Staking Basket program, to appear credible. The attackers have replicated the original Eternl Desktop announcement, including information about hardware wallet compatibility and advanced delegation controls.
The phishing email maintains a professional appearance, with no spelling or grammar errors, to effectively deceive recipients. It utilizes the domain download.eternldesktop.network to distribute a malicious installer package without proper verification or digital signature validation.
Malware analyst Anurag identified the malicious installer, revealing it contains a hidden LogMeIn Resolve remote management tool. This discovery highlights a supply-chain abuse attempt aimed at gaining unauthorized system access.
A phishing campaign targeting Cardano users has been identified, posing risks to those attempting to download the Eternl Desktop application.
The malicious MSI installer, approximately 23.3 megabytes with hash 8fa4844e40669c1cb417d7cf923bf3e0, installs an executable named unattended-updater.exe, originally known as GoToResolveUnattendedUpdater.exe. During runtime, it creates a unique folder structure under the system’s Program Files directory and writes several configuration files, such as unattended.json and logger.json.
The unattended.json file facilitates remote access without user interaction. The executable attempts connections with GoTo Resolve services, including devices-iot.console.gotoresolve.com. Network analysis reveals that system event information is transmitted in JSON format to remote servers using hardcoded API credentials, establishing a channel for command execution and monitoring.
This behavior is classified as critical, as remote management tools can allow threat actors to maintain long-term system access, execute remote commands, and harvest credentials. The campaign demonstrates the misuse of cryptocurrency governance narratives to distribute covert access tools. Users are advised to verify software authenticity through official channels and avoid downloading applications from unverified sources.
Based on reporting by Cyber Security News.
