Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement
ID: 88f242bc-7446-5221-886b-ea8077f3f5d1
STIX ID: report--88f242bc-7446-5221-886b-ea8077f3f5d1
Feed Name: cybersecurityNews.com
A sophisticated phishing campaign targeting the Cardano community is distributing a malicious Eternl Desktop MSI from the domain download.eternldesktop.network that masquerades as an official wallet announcement. The 23.3 MB installer (hash 8fa4844e40669c1cb417d7cf923bf3e0) drops an executable (GoToResolveUnattendedUpdater.exe / unattended-updater.exe) which creates configuration files (including unattended.json) to enable stealthy remote access, communicates with GoTo Resolve infrastructure (e.g., devices-iot.console.gotoresolve.com) using hardcoded API credentials, and demonstrates supply-chain abuse and risk of long-term persistence and credential theft; users are advised to verify downloads via official channels and avoid newly registered domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
