COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It
COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It 1. Basic Information Article Title : COLDCARD security audit phishing attack installs remote access tool Publisher : BleepingComputer Publication Date : August 5, 2026 Original Source : BleepingComputer Related Information Source : Proofpoint (campaign discovery and IOC sharing) Related Malware and Tools : ConnectWise ScreenConnect, Coldcard_Diagnostic_Tool.bat , setup.msi , docusign.exe , certutil.exe , PowerShell Related Products and Services : COLDCARD hardware wallet, GitHub, Windows, DocuSign printer driver Related CVE and Threat Group : No CVE. Threat group not identified. Severity : High Attackers used recent news about COLDCARD random number issues and the theft of about 88.6 million dollars in Bitcoin. They contacted hardware wallet users and pretended to run a security audit before August 10. The targets did not need to give their recovery seeds, so they thought the email was real. A live chat operator guided them until they approved the UAC prompt. 2. One-Sentence Summary A fake security audit email and support chat trick users into feeling safe. The user downloads a large batch file from GitHub. The file contains a hidden ScreenConnect MSI installer. The system uses certutil to decode and install it with administrator rights. This leads to remote control via a legitimate RMM tool, cryptocurrency theft, and potential follow-up malware or ransomware. 3. Attack Flow Chain A: Audit Notice to Chat Guidance The attacker sends an email from compliance@coldcardteamnews.com with the subject Hardware audit now available . The email states that an urgent audit is required for all hardware revisions, with a deadline of August 10. It directs the user to a fake Security Verification & Incident Reporting Tool at coldcardcompliance.com . It lowers the user's guard by saying the process is "air-gapped" and "does not ask for recovery seeds." A live chat operator c