COLDCARD ScreenConnect phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device takeover and cryptocurrency theft. The operation impersonates COLDCARD with spoofed emails and a lookalike website, then pressures users through live chat to approve the installation. It is tied to a broader trust exploit around the recently disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft.
Related Happenings
ConnectWise ScreenConnect remote access installation chain
Malware Activity
H score29
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
How related:
The MSI launched setup.msi file is actually a ConnectWise ScreenConnect installer, which is a remote management tool that gives the threat actor remote access to the device.
About this happening:
A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
ConnectWise ScreenConnect remote access installation chain
Malware ActivityHow related: The MSI launched setup.msi file is actually a ConnectWise ScreenConnect installer, which is a remote management tool that gives the threat actor remote access to the device.
About this happening: A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
COLDCARD wallet random number generation security flaw
Vulnerability
H score42
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
How related:
The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions.
About this happening:
A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affec...
COLDCARD wallet random number generation security flaw
VulnerabilityHow related: The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions.
About this happening: A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affec...
NFCShare fake banking-app update phishing campaign
Campaign
H score40
First: 09.06.2026 01:11
Last: 09.06.2026 01:11
Sources 1
About this happening:
The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding...
NFCShare fake banking-app update phishing campaign
CampaignAbout this happening: The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding...
NFCShare Android malware spreads via fake banking-app updates
Malware Activity
H score21
First: 09.06.2026 01:11
Last: 09.06.2026 01:11
Sources 1
About this happening:
The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
NFCShare Android malware spreads via fake banking-app updates
Malware ActivityAbout this happening: The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Latest development: 05.08.2026 14:43
Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.
Timeline
-
05.08.2026 20:49 2 articles · 1h ago
COLDCARD impersonation campaign pushes fake audit and ScreenConnect install
Initial DisclosureProofpoint says phishing operators are impersonating COLDCARD with emails from [email protected] and a lookalike coldcardcompliance.com site that claims a security audit is underway, directs recipients to a "Security Verification & Incident Reporting Tool" due by August 10, and pushes a batch-file download that installs ConnectWise ScreenConnect for remote access.
Show sources
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49