Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    August 5, 2026

    Senator Lummis Still Pushing for CLARITY Vote Before August Recess

    August 5, 2026

    80-million-year-old snake brain reveals a surprising evolutionary secret

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
    • Senator Lummis Still Pushing for CLARITY Vote Before August Recess
    • 80-million-year-old snake brain reveals a surprising evolutionary secret
    • The Guardian view on French cinema’s De Gaulle moment: present anxieties inform a new focus on the past | Editorial
    • Did Trump post AI image of himself with Generals Patton and MacArthur?
    • Vollering wins stage 5 as Reusser clings to Tour de Femmes lead
    • After deadly Kyiv strike, Ukraine warns interceptor shortage is costing lives
    • Student loan repayment rates an ‘unsustainable burden’, chancellor told
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    COLDCARD security audit phishing attack installs remote access tool

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.

    Proofpoint, which discovered the campaign, says it uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.

    The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions.

    image

    The emails are sent from compliance@coldcardteamnews.com with the subject “Hardware audit now available” and tell recipients that recent findings require COLDCARD to verify the integrity of devices across all hardware revisions.

    “We are writing to inform you of a coordinated security audit now underway across the COLDCARD device network. Recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed,” reads the fake security audit emails.

    COLDCARD phishing email
    COLDCARD phishing email
    Source: Proofpoint

    The emails direct users to an alleged “Security Verification & Incident Reporting Tool,” claiming the process is air-gapped, will not request their recovery seed, and must be completed by August 10.

    Clicking an “Access the Audit Tool” button opens the site coldcardcompliance.com, which impersonates COLDCARD with a message to click on the “Start Hardware Audit” button to download the tool.

    The fake website also includes a live “Customer Service” chat feature that allegedly allows targets to receive support for their COLDCARD devices.

    In chats shared by Proofpoint, an operator asks whether the victim uses Windows or macOS and then instructs Windows users to run the downloaded tool.

    Chat feature on the phishing site
    Chat feature on the phishing site
    Source: Proofpoint

    When one user reported seeing a black window and an administrator prompt, the operator explained that the prompt was required to begin the installation and told them to click “Yes.”

    Proofpoint believes these conversations are likely being handled by real people rather than an automated chatbot, allowing the attackers to respond to concerns and pressure hesitant victims into proceeding with the installation.

    Batch file installs remote access software

    Proofpoint shared on X that clicking on the website’s “Start Hardware Audit” button downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account.

    BleepingComputer analyzed the 25.7MB batch file shared by Proofpoint and found that it contains two Base64-encoded files embedded directly in the file.

    When launched, the script first pretends to perform a diagnostic check on your device, but in the background it actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.

    Fake COLDCARD diagnostic tool
    Fake COLDCARD diagnostic tool
    Source: BleepingComputer

    The script then stores the embedded Base64-encoded files in a randomly named directory as setup.msi [VirusTotal] and docusign.exe [VirusTotal] in the Windows temp folder and decodes them using Windows certutil.

    After installing the setup.msi file, the script launches docusign.exe, displays an “Installation Complete” message, and then deletes the temporary directory. The docusign.exe file is a legitimate signed executable that installs a DocuSign printer driver, which acts as a decoy during the attack.

    The MSI launched setup.msi file is actually a ConnectWise ScreenConnect installer, which is a remote management tool that gives the threat actor remote access to the device.

    When launched, Proofpoint says it connects to the activeretirementrelocation[.]com, which is the ScreenConnect command-and-control server used by the threat actor.

    Once connected through ScreenConnect, the attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.

    Proofpoint warns that this access could also be used to deploy ransomware.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    access attack audit Coldcard Installs Phishing remote Security tool
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

    The top new cybersecurity products at Black Hat USA 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)

    How AI-powered phishing killed blocklists for good

    The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    August 5, 2026

    Senator Lummis Still Pushing for CLARITY Vote Before August Recess

    August 5, 2026

    80-million-year-old snake brain reveals a surprising evolutionary secret

    August 5, 2026

    The Guardian view on French cinema’s De Gaulle moment: present anxieties inform a new focus on the past | Editorial

    August 5, 2026
    Latest Posts

    Can you identify Taylor Farms products by codes beginning with ‘TF’ printed on bags?

    July 23, 2026

    The Guardian view on Britain’s uninhabitable homes: as temperatures rise, a new approach is needed | Editorial

    July 23, 2026

    Can Wisconsin voters void a returned absentee ballot?

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

    August 5, 2026

    Senator Lummis Still Pushing for CLARITY Vote Before August Recess

    August 5, 2026

    80-million-year-old snake brain reveals a surprising evolutionary secret

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.