Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Stablecoins Enter Institutional Phase As Senate CLARITY Draft Clarifies Rules – Analyst

May 14, 2026

XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

May 14, 2026

Kelp DAO Unpauses rsETH Withdrawals After Tranche Transfer

May 13, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Bitcoin

Fake emails target Cardano users with remote access malware

By WebDeskJanuary 3, 20262 Mins Read
Fake emails target Cardano users with remote access malware
Share
Facebook Twitter LinkedIn Pinterest Email

A phishing campaign is targeting Cardano users through fake emails promoting a fraudulent Eternl Desktop application download.

The attack leverages professionally crafted messages referencing NIGHT and ATMA token rewards through the Diffusion Staking Basket program to establish credibility.

Threat hunter Anurag identified a malicious installer distributed through a newly registered domain, download.eternldesktop.network.

The 23.3 megabyte Eternl.msi file contains a hidden LogMeIn Resolve remote management tool that establishes unauthorized access to victim systems without user awareness.

Fake installer bundles remote access trojan

The malicious MSI installer carries a specific and drops an executable called unattended-updater.exe with the original filename. During runtime, the executable creates a folder structure under the system’s Program Files directory.

The installer writes multiple configuration files including unattended.json, logger.json, mandatory.json, and pc.json.

The unattended.json configuration enables remote access functionality without requiring user interaction.

Network analysis reveals the malware connects to GoTo Resolve infrastructure. The executable transmits system event information in JSON format to remote servers using hardcoded API credentials.

Security researchers classify the behavior as critical. Remote management tools provide threat actors with capabilities for long-term persistence, remote command execution, and credential harvesting once installed on victim systems.

The phishing emails maintain a polished, professional tone with proper grammar and no spelling errors.

The fraudulent announcement creates a nearly identical replica of the official Eternl Desktop release, complete with messaging about hardware wallet compatibility, local key management, and advanced delegation controls.

Campaign targets Cardano users

The attackers weaponize cryptocurrency governance narratives and ecosystem-specific references to distribute covert access tools.

References to NIGHT and ATMA token rewards through the Diffusion Staking Basket program lend false legitimacy to the malicious campaign.

Cardano users seeking to participate in staking or governance features face high risk from social engineering tactics that mimic legitimate ecosystem developments.

The newly registered domain distributes the installer without official verification or digital signature validation.

Users should verify software authenticity exclusively through official channels before downloading wallet applications.

Anurag’s malware analysis revealed the supply-chain abuse attempt aimed at establishing persistent unauthorized access.

The GoTo Resolve tool provides attackers with remote control capabilities that compromise wallet security and private key access.

Users should avoid downloading wallet applications from unverified sources or newly registered domains regardless of email polish or professional appearance.

Credit: Source link

Previous ArticleTelegram Introduces AI Summaries and New Design Enhancements
Next Article Crypto News & Airdrop Update – Venezuela Takes Center Stage

Related Posts

Stablecoins Enter Institutional Phase As Senate CLARITY Draft Clarifies Rules – Analyst

May 14, 2026

XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

May 14, 2026

Corpay Partners BVNK to Launch Stablecoin Payments Across $12 Billion Global Network

May 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Stablecoins Enter Institutional Phase As Senate CLARITY Draft Clarifies Rules – Analyst

May 14, 2026

XRP Holds Key Level, But Binance Flow Data Signals Weakening Demand

May 14, 2026

Kelp DAO Unpauses rsETH Withdrawals After Tranche Transfer

May 13, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Danish Ice Hockey Federation Appoints Concordium as AI Partner, Introduces Digital Identity Pilot at IIHF World Championship

Shiba Inu’s $0.000006 Resistance Is Proving Difficult: Here’s Why

XRP Price Prediction: Funding Rates Have Been Negative for 3 Months While XRP Is Up 27%

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$79,406.00-2.16%
  • ethereumEthereum(ETH)$2,257.22-2.02%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$667.87-1.89%
  • rippleXRP(XRP)$1.43-2.04%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$90.52-5.08%
  • tronTRON(TRX)$0.3505710.37%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.62%
  • dogecoinDogecoin(DOGE)$0.1133200.78%
  • whitebitWhiteBIT Coin(WBT)$58.43-2.00%
  • USDSUSDS(USDS)$1.000.02%
  • cardanoCardano(ADA)$0.264753-3.45%
  • leo-tokenLEO Token(LEO)$10.070.75%
  • HyperliquidHyperliquid(HYPE)$38.61-3.95%
  • zcashZcash(ZEC)$527.84-5.98%
  • bitcoin-cashBitcoin Cash(BCH)$433.26-2.14%
  • chainlinkChainlink(LINK)$10.20-2.53%
  • moneroMonero(XMR)$398.97-3.38%
  • CantonCanton(CC)$0.1563501.13%
  • the-open-networkToncoin(TON)$2.13-6.65%
  • stellarStellar(XLM)$0.159417-3.31%
  • suiSui(SUI)$1.21-2.78%
  • USD1USD1(USD1)$1.00-0.01%
  • litecoinLitecoin(LTC)$57.05-2.29%
  • daiDai(DAI)$1.000.00%
  • MemeCoreMemeCore(M)$3.341.73%
  • avalanche-2Avalanche(AVAX)$9.72-3.21%
  • hedera-hashgraphHedera(HBAR)$0.093244-1.64%
  • Ethena USDeEthena USDe(USDE)$1.000.07%
  • shiba-inuShiba Inu(SHIB)$0.000006-4.04%
  • RainRain(RAIN)$0.007466-1.62%
  • paypal-usdPayPal USD(PYUSD)$1.000.02%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • crypto-com-chainCronos(CRO)$0.073467-7.68%
  • Circle USYCCircle USYC(USYC)$1.120.00%
  • BittensorBittensor(TAO)$295.09-4.83%
  • tether-goldTether Gold(XAUT)$4,690.91-0.17%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • uniswapUniswap(UNI)$3.60-5.55%
  • polkadotPolkadot(DOT)$1.33-4.91%
  • mantleMantle(MNT)$0.680.33%
  • pax-goldPAX Gold(PAXG)$4,691.70-0.18%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0690850.77%
  • nearNEAR Protocol(NEAR)$1.55-6.19%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.61%
  • OndoOndo(ONDO)$0.377993-6.49%
  • Pi NetworkPi Network(PI)$0.170722-1.08%
  • Falcon USDFalcon USD(USDF)$1.00-0.23%
  • okbOKB(OKB)$84.38-2.01%