Snail mail letters target Trezor and Ledger users in crypto-theft attacks
ID: f004f3c4-18ae-583e-a2a8-fa590b3cb78b
STIX ID: report--f004f3c4-18ae-583e-a2a8-fa590b3cb78b
Feed Name: Bleeping Computer
A phishing campaign is mailing letters that impersonate Trezor and Ledger, instructing recipients to scan QR codes for a supposed "Authentication/Transaction Check"; the QR codes lead to phishing sites that ask for hardware wallet recovery phrases and transmit them to an attacker-controlled API endpoint (e.g., https://trezor.authentication-check.io/black/api/send.php). The campaign leverages physical mail to create urgency and trust, has produced live phishing domains (one flagged by Cloudflare), and threatens complete loss of funds for any user who submits their seed phrase.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
