Affected Systems
COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub. Affects Windows users who execute the file with administrator privileges. ScreenConnect C2 server: activeretirementrelocation[.]com. Phishing domains: coldcardteamnews.com, coldcardcompliance.com.
Exploitation Status
Active exploitation confirmed. Proofpoint discovered live phishing campaign with real-time operator support via chat feature on phishing site. Campaign leverages recent COLDCARD RNG vulnerability and $88.6 million Bitcoin theft (1,367 BTC from 4,585 addresses) as social engineering lure. Deadline pressure applied (August 10 audit completion).
Business Impact
Threat actors gain full remote access to victim systems via ScreenConnect, enabling data exfiltration, cryptocurrency theft, credential harvesting, and potential ransomware deployment. Campaign demonstrates sophisticated social engineering with live operator support to overcome victim hesitation. Targets cryptocurrency holders, increasing likelihood of high-value theft. No CVE assigned; this is a phishing/social engineering campaign rather than a software vulnerability.
Urgency
🔴 Immediate
Recommended Actions
- Block domains coldcardteamnews.com, coldcardcompliance.com, and activeretirementrelocation[.]com at DNS/proxy level
- Hunt for ScreenConnect installations connecting to activeretirementrelocation[.]com; check endpoint logs for setup.msi and docusign.exe in %TEMP% directories
- Alert users holding cryptocurrency wallets about fake COLDCARD security audit emails from compliance@coldcardteamnews.com with subject 'Hardware audit now available'
- Block execution of Coldcard_Diagnostic_Tool.bat (hash available on VirusTotal); monitor for certutil.exe decoding Base64 files from batch scripts
- Review ScreenConnect/ConnectWise installations for unauthorized instances; validate all remote access tool deployments against asset inventory
