bleeping-computer · Crawled Aug 5, 2026

COLDCARD security audit phishing attack installs remote access tool

6 IoCs
Read original article ↗

AI Summary

A phishing campaign impersonating COLDCARD is distributing a malicious batch file named Coldcard_Diagnostic_Tool.bat, which installs ScreenConnect remote access software to gain persistent control over victims' systems. The attack leverages fears around a recent COLDCARD wallet vulnerability and a $88.6 million Bitcoin theft, using spoofed emails and a fake website (coldcardcompliance.com) to trick users into downloading the payload. The batch file drops and executes a signed ScreenConnect installer disguised as a legitimate diagnostic tool, connecting to a command-and-control server at activeretirementrelocation[.]com, enabling remote access, data theft, and potential ransomware deployment.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
Domain coldcardcompliance[.]com Details →
Domain activeretirementrelocation[.]com Details →
Filename Coldcard_Diagnostic_Tool.bat Details →
Filename setup.msi Details →
Filename docusign.exe Details →
GitHub Repo Coldcard_Diagnostic_Tool.bat Details →