Phishing Campaign Targets COLDCARD Users with Malicious Batch File
A sophisticated phishing campaign is actively targeting users of COLDCARD, a popular hardware wallet for Bitcoin. The attack, discovered by Proofpoint and detailed by BleepingComputer, leverages a large 25.7MB batch file disguised as a diagnostic tool to deploy the remote access software ConnectWise ScreenConnect. The campaign's ingenuity lies in its social engineering tactics, which often involve direct chat communication to persuade victims into executing the malicious file.
The attackers have created a convincing lure, presenting the malicious payload as a necessary step for a "COLDCARD security audit." This framing preys on the security-conscious nature of cryptocurrency users, making them more susceptible to executing unfamiliar files under the guise of necessary maintenance or verification. The sheer size of the batch file (Coldcard_Diagnostic_Tool.bat) is itself a subtle indicator of something unusual, as typical diagnostic tools are rarely that large. However, the social engineering aspect, including personalized chat interactions, aims to bypass this initial suspicion.
Once executed, the batch file does not directly run ScreenConnect. Instead, it acts as a dropper, extracting and executing a staged payload. This often involves a file named setup.msi, which is an MSI package designed to install the legitimate, but compromised, version of ConnectWise ScreenConnect. The use of a legitimate tool like ScreenConnect is a common tactic by threat actors, as it bypasses many security controls that might flag entirely unknown executables. The tool is then used to establish persistent remote access to the victim's system, allowing attackers to steal sensitive information or cryptocurrency.

Technical Execution and Payload Delivery
The Coldcard_Diagnostic_Tool.bat file is designed to unpack and execute a series of commands. It frequently utilizes legitimate Windows utilities such as certutil.exe for file decoding and PowerShell for executing scripts. This multi-stage approach makes it harder for basic antivirus software to detect the malicious activity, as each individual step might appear benign.
The batch script first decodes a Base64 encoded string, which contains the actual payload. This payload is then written to a temporary file, often named setup.msi. This MSI package is a custom installer for ConnectWise ScreenConnect. The attackers have likely tampered with the legitimate ScreenConnect installer to include malicious components or to facilitate easier unattended installation and connection back to their command-and-control infrastructure.
The use of docusign.exe, also mentioned in relation to this campaign, could be another decoy or a component used in the unpacking process, further obfuscating the true nature of the operation. The ultimate goal is to establish a covert channel for remote access, turning the victim's machine into a gateway for further compromise. The attackers are adept at maintaining communication through chat platforms, providing just enough plausible deniability and instruction to guide the victim through the execution process.
Social Engineering and Target Profile
The primary targets of this campaign appear to be individuals and entities involved in cryptocurrency, specifically those using or auditing COLDCARD hardware wallets. The attackers leverage the inherent need for security and verification within this community. By framing the attack as a "security audit" or "diagnostic tool," they exploit the users' desire to ensure their digital assets are safe.
The campaign's reliance on direct chat communication is particularly concerning. This allows attackers to tailor their approach, respond to user questions, and build a sense of trust or urgency. They can guide users through disabling security features or accepting UAC (User Account Control) prompts, which are critical steps in executing such payloads. This human-element interaction bypasses automated defenses that might catch a direct email or file download without context.
Proofpoint's involvement in discovering and sharing indicators of compromise (IOCs) highlights the widespread nature and potential impact of this attack. While the specific publication date of the BleepingComputer article is August 5, 2026, the ongoing nature of such phishing campaigns suggests that similar tactics could resurface or evolve. The large file size of the initial batch file, while suspicious, is hidden behind layers of social engineering and technical obfuscation.
Mitigation and Defense Strategies
For COLDCARD users and anyone in the cryptocurrency space, vigilance is paramount. Never execute diagnostic tools or security audit files from unknown or unverified sources, even if they arrive through direct chat or seemingly reputable channels. Always verify the source of any file before execution.
Verify any requests for executing software through official COLDCARD support channels. The company itself would not typically request users to run arbitrary diagnostic tools downloaded from unverified sources. Furthermore, maintaining up-to-date antivirus software and being cautious of User Account Control (UAC) prompts are essential. If a prompt appears unexpectedly or for a file you didn't intend to run, it is a strong indicator of a potential threat.
For organizations, implementing robust email and endpoint security solutions is crucial. Employee training on phishing awareness, especially regarding social engineering tactics used in direct messaging, can significantly reduce the success rate of such attacks. Network monitoring for unusual outbound connections, particularly to known malicious infrastructure or for remote access tools like ScreenConnect, can also provide early detection.
The use of legitimate tools like ConnectWise ScreenConnect by attackers underscores the need to monitor for unauthorized installations or usage of such remote management software. Organizations should have strict policies regarding the deployment and use of RMM (Remote Monitoring and Management) tools and regularly audit their systems for unauthorized instances.
The technical sophistication, combined with effective social engineering, makes this campaign a notable threat. By understanding the mechanics of the attack and maintaining a heightened sense of security awareness, users can better protect themselves from falling victim to this COLDCARD audit phishing scheme.
