COLDCARD Audit Phishing: 25.7MB Batch File Embeds ScreenConnect and Uses Chat to Trick Admins into Running It
1. Basic Information
- Article Title: COLDCARD security audit phishing attack installs remote access tool
- Publisher: BleepingComputer
- Publication Date: August 5, 2026
- Original Source: BleepingComputer
- Related Information Source: Proofpoint (campaign discovery and IOC sharing)
-
Related Malware and Tools: ConnectWise ScreenConnect,
Coldcard_Diagnostic_Tool.bat,setup.msi,docusign.exe,certutil.exe, PowerShell - Related Products and Services: COLDCARD hardware wallet, GitHub, Windows, DocuSign printer driver
- Related CVE and Threat Group: No CVE. Threat group not identified.
- Severity: High
Attackers used recent news about COLDCARD random number issues and the theft of about 88.6 million dollars in Bitcoin. They contacted hardware wallet users and pretended to run a security audit before August 10. The targets did not need to give their recovery seeds, so they thought the email was real. A live chat operator guided them until they approved the UAC prompt.
2. One-Sentence Summary
A fake security audit email and support chat trick users into feeling safe. The user downloads a large batch file from GitHub. The file contains a hidden ScreenConnect MSI installer. The system uses certutil to decode and install it with administrator rights. This leads to remote control via a legitimate RMM tool, cryptocurrency theft, and potential follow-up malware or ransomware.
3. Attack Flow
Chain A: Audit Notice to Chat Guidance
- The attacker sends an email from
compliance@coldcardteamnews.comwith the subjectHardware audit now available. - The email states that an urgent audit is required for all hardware revisions, with a deadline of August 10.
- It directs the user to a fake
Security Verification & Incident Reporting Toolatcoldcardcompliance.com. - It lowers the user's guard by saying the process is "air-gapped" and "does not ask for recovery seeds."
- A live chat operator checks if the user is on Windows or macOS.
- The operator answers questions about black windows or UAC prompts in real time and tells the user to run the tool.
Chain B: Batch File to RMM Deployment
- The user clicks
Start Hardware Auditand downloads a 25.7MB file namedColdcard_Diagnostic_Tool.batfrom GitHub. - The batch file shows a fake diagnostic screen and checks for administrator rights.
- If the user is not an administrator, the script restarts itself using PowerShell and asks for UAC elevation.
- It saves embedded Base64 data to a random temporary directory.
- It uses
certutilto decodesetup.msianddocusign.exe. - It installs the ScreenConnect client using
setup.msi. - It installs the DocuSign printer driver using the legitimate signed
docusign.exefile to show a decoy screen. - It shows an
Installation Completemessage and deletes the temporary directory.
Chain C: Remote Control
- ScreenConnect connects to
activeretirementrelocation[.]com. - The attacker takes remote control of the device.
- The attacker can search for wallets, credentials, and data, deploy more malware, or send cryptocurrency.
- Ransomware deployment is possible under certain conditions, but the article does not confirm later damage.
4. Attacker Locations and Execution Sites
- Guidance: Fake sender domain, fake COLDCARD site, live chat
- Payload Distribution: Attacker-controlled GitHub account
- Execution Site: Victim's Windows device
- Privilege Escalation: PowerShell self-relaunch and UAC prompt
-
Remote Access / C2: ScreenConnect server
activeretirementrelocation[.]com - Decoy: Legitimate signed DocuSign printer driver installer
5. What Victims and Administrators See
The user sees an urgent audit from the hardware wallet vendor, live chat support, a black diagnostic window, a UAC prompt, a DocuSign driver, and a completion message. The SOC sees a batch file download, PowerShell elevation, certutil decoding, an MSI installation, a ScreenConnect service/client, and persistent traffic to an unknown domain. Because the attack uses a legitimate RMM and a signed decoy, simple malware hash checks easily miss it.
6. Success and Failure Conditions
Success Conditions
- A COLDCARD user trusts the fear-based email.
- The user clicks the email link or visits the fake site.
- The user downloads and runs the batch file.
- The user approves the UAC prompt.
- ScreenConnect installation and C2 egress are allowed.
- RMM application control is not installed.
Failure Conditions
- The user checks the vendor domain, electronic signature, or official announcements through another channel.
- The email or web gateway blocks the sender, domain, or payload.
- EDR blocks the batch, PowerShell,
certutil, and MSI chain. - The network restricts the installation, service, and egress of unauthorized RMM tools.
- Standard user accounts are enforced and UAC requests are denied.
7. What Happens on Success
Through ScreenConnect, the attacker can control the device using the same screen and permissions as the user. They can search the wallet application, browser, password manager, clipboard, and local files. They can steal cryptocurrency, credentials, and data, and deploy additional payloads or ransomware. The public article does not confirm specific damage after the ScreenConnect connection.
8. Observable Logs
- Sender:
compliance@coldcardteamnews.com - Subject:
Hardware audit now available - Body emphasizes audit deadlines, air-gapped status, and no requirement for seeds.
- Link to
coldcardcompliance.com.
Proxy / SWG / DNS
coldcardcompliance.com- Download of
.batfile from the attacker's GitHub account - ScreenConnect traffic to
activeretirementrelocation[.]com
Endpoint / EDR
Coldcard_Diagnostic_Tool.bat- Batch file launching PowerShell for self-elevation
- Base64 decoding using
certutil -
setup.msianddocusign.exeinside a random%TEMP%directory - MSI installation, ScreenConnect service/client creation
- Deletion of the temp directory
Identity / IdP
- No corporate identity used in the early stages.
- Remote operator browser and credential access are subjects for later investigation.
SaaS / Cloud
- GitHub repository or account download audits are hard for organizations to collect.
- If available, ScreenConnect session and server logs should be preserved.
Network
- ScreenConnect-specific persistent connection
- Remote access server connection right after installation
- Later traffic to wallets, exchanges, or additional payloads
9. Attack Success Stages
- Contact Only: Received fake audit email
- User Action: Clicked link, visited fake site, downloaded batch file
- Initial Execution: Ran batch file, showed diagnostic screen
- Privilege Gain: Approved UAC and re-ran as administrator
- Malware / RMM Success: Installed ScreenConnect, registered service, connected to C2
- Session Compromise: Started remote session, operator ran commands, keyboard, or mouse actions
- Data Theft: Confirmed access and outbound transfer of wallets, credentials, and files
- Follow-on Compromise: Confirmed cryptocurrency transfer, additional malware, or ransomware
10. Investigation Playbook
Trigger
- COLDCARD audit email
Coldcard_Diagnostic_Tool.bat- Unauthorized ScreenConnect
activeretirementrelocation[.]com
Initial Checks
- Preserve email headers, body, URLs, attachments, and downloads.
- Record the exact times of clicks, downloads, execution, and UAC prompts.
- Check the ScreenConnect installation time and the first C2 connection.
Device
- Process tree for batch, PowerShell,
certutil, andmsiexec - Temporary files, MSI products/services, and ScreenConnect configuration
- Processes, files, browser history, and clipboard artifacts during the remote session
- Wallet applications, exchange access, and additional payloads
Authentication and Cloud
- Create an inventory of passwords, browser sessions, and wallet keys found on the endpoint.
- Revoke and rotate sessions for exchanges, email, cloud services, and password managers.
- Check cryptocurrency transactions.
Follow-up Actions
- Look for additional persistence, scheduled tasks, services, and new user accounts.
- Check for ransomware tools, data staging, and remote commands.
- Search for other recipients of the same email campaign.
Containment
- Isolate the device from the network.
- Preserve evidence before stopping the ScreenConnect service.
- Block the domain, sender, and GitHub URL.
- Consider moving cryptocurrency assets to a new wallet on a clean device.
- Rotate all credentials and sessions.
Assessment Categories
- Phishing Delivered / Link Clicked / Script Executed / Elevated / ScreenConnect Connected / Remote Session Confirmed / Data or Crypto Theft Confirmed / Follow-on Malware Confirmed
11. Defense and Detection Ideas
Single Events
- PowerShell elevation triggered by a
.batfile -
certutildecoding triggered by a batch file or PowerShell - MSI installation inside a temporary folder
- New ScreenConnect service creation
Timeline Correlation
email → fake site → GitHub batch → UAC → certutil → msiexec → ScreenConnect service → remote C2
Threat Hunting Focus
- Matching subjects, senders, and domains
- Large batch files around 25MB with embedded Base64 data
- Connection to an unknown server immediately after installing a legitimate RMM
- Simultaneous execution of a DocuSign decoy and ScreenConnect
Log Gaps
- Email click telemetry
- Complete command lines and script block logs
- MSI and service installation events
- RMM session and operator logs
- Wallet application access
Priority Countermeasures
- Allowlist or block unauthorized RMM tools
- EDR rules for the batch → LOLBins → MSI chain
- Procedures to verify urgent hardware wallet notifications
- Training for standard user accounts and UAC prompts
- Incident response procedures for cryptocurrency users
12. Facts, Inference, and Hypothesis
Facts
- Proofpoint discovered a campaign impersonating COLDCARD.
- A fake site and live chat guided users until they approved UAC.
- The 25.7MB batch file contained two Base64 files.
-
certutildecoded a ScreenConnect MSI and a legitimate DocuSign decoy. - ScreenConnect connected to
activeretirementrelocation[.]com. - Subsequent data or cryptocurrency theft and ransomware are capabilities; actual damage was not confirmed in the article.
Inference
- Explaining that recovery seeds are not required is designed to bypass the caution of security-aware hardware wallet users.
- Live operators change their guidance based on technical warnings to bypass static training.
Hypothesis
- Data on COLDCARD buyers or cryptocurrency enthusiasts might have been used for target selection.
- Campaigns impersonating other brands might be launched from the same ScreenConnect server.
13. MITRE ATT&CK Mapping
High Confidence
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.003 Windows Command Shell
- T1059.001 PowerShell
- T1140 Deobfuscate/Decode Files or Information
-
T1218.013 (Note:
certutilis best treated as T1140/T1105 rather than Mavinject, etc.) - T1219.002 Remote Access Software
- T1543.003 Windows Service
- T1105 Ingress Tool Transfer
Medium Confidence
- T1036 Masquerading: Diagnostic and DocuSign decoys
- T1071.001 Web Protocols: ScreenConnect traffic
- T1555 Credentials from Password Stores: Follow-up capability, execution unconfirmed
- T1657 Financial Theft: If cryptocurrency theft is completed
- T1486 Data Encrypted for Impact: Ransomware deployment unconfirmed
14. Unknowns and Additional Investigation
- Number of campaign emails sent, target regions, and recipient sources
- Hashes of the batch file, MSI, and
docusign.exe - GitHub account and repository URLs
- ScreenConnect tenant and operator identities
- Commands and data theft after the remote session
- Actual cryptocurrency losses
- Payloads presented to macOS users
15. Impact on SOCs and General Enterprises
Legitimate remote management tools are common for support purposes in many organizations, and security teams often cannot block ScreenConnect simply as an IOC. Analysts must combine installation origins, parent processes, initial connection destinations, and approved RMM inventories. Employees, executives, and developers who handle cryptocurrency can become targets even on enterprise devices, so teams should not dismiss personal asset fraud as outside the scope of a corporate SOC.
16. Summary for SOCs, Administrators, and Users
For SOCs
- Detect the batch → PowerShell → certutil → MSI → ScreenConnect chain as a single sequence.
- Treat unauthorized RMM tools as high-priority investigations, even if they are digitally signed.
- Check endpoints, email, and wallet/exchange access together.
For Administrators
- Enforce RMM allowlists and monitor service installations.
- Verify urgent hardware wallet notifications through official channels.
- Completely rotate credentials and sessions on infected devices.
For Users
- Do not download tools or approve UAC prompts from email links, even if sent by a hardware wallet vendor.
- Just because a tool does not ask for your recovery seed does not mean it is safe.
- If you run the file, disconnect the device from the network and contact the security team from a clean device.
Top comments (8)
The live chat part really stands out. It seems like it was doing more than making the site feel legitimate it almost worked as a human exception handler.
If the victim hesitated at the black window, UAC prompt, or installation step, the operator could respond in real time and explain why it was supposedly normal. That turns the warnings meant to interrupt the attack into feedback that helps the attacker adjust.
The “we won’t ask for your recovery seed” line is interesting too. It sounds like they understood what security conscious wallet users had been taught and used that familiar safety rule to make everything else feel trustworthy.
It made me wonder whether support related security guidance should include a kind of forced channel break: if a conversation suddenly leads to UAC, script execution, or remote access software, stop and verify through a separately located vendor contact instead of asking the same person whether the warning is safe.
ScreenConnect raises a similar question. The software itself was legitimate and signed, but the server controlling it and the way it was installed were not. Maybe RMM trust needs to include not only the binary, but also the expected tenant, deployment source, parent process, and destination.
Your “forced channel break” idea actually reminded me of The Beekeeper, which I watched recently. There’s a scene where an older woman is tricked by a fake support operator into installing remote access software. She becomes suspicious, but the attacker creates a sense of urgency and convinces her that stopping would make things worse, so she keeps going.
That was actually one of the first things I thought about when I saw this incident. Even when people feel that something is wrong, it can be very hard to stop and verify things when someone is pressuring them to make a decision right now.
So I agree with your idea, but it also makes me think that awareness alone probably isn’t enough. We may need more technical friction at that point too. For example, when remote access software is installed, the OS or security software could show a very explicit warning about support scams and encourage the user to verify the request through a separate channel before continuing.
That kind of warning would probably be annoying for experienced users, but for people who rarely use RMM tools, it might be a useful safeguard.
Yeah, I think that distinction between awareness and actual friction is important. Generic warnings can easily become something people click through without thinking. It might be more useful if the warning explained what was unusual, like the remote access tool coming from a browser download, connecting to an unfamiliar tenant, or not being deployed by the user’s organization.
I’m aware of The Beekeeper, but I’ve never actually seen it. From the scene you described, though, it sounds like the same basic problem the person creating the danger is also the one answering every doubt the victim has. That’s where forcing them to stop and verify somewhere else could really help.
Yeah, I agree. A warning that explains why the situation is unusual would probably be much more useful than another generic “Are you sure?” prompt.
And that’s exactly the part of The Beekeeper example I had in mind. The person creating the danger is also the one answering every concern, so the victim never really gets an independent point of reference. That makes the idea of forcing a separate verification step feel even more important.
I honestly I wrote that movie off as another cheesy looking Jason statin movie but sounds a little more thought provoking than I would have gave it based off trailers. Unless you are talking about another movie.
Haha, yes, I mean the Jason Statham movie 😄
And honestly, you’re not wrong. The overall story is pretty much a classic retired-killer revenge movie, and it definitely reminded me of John Wick. I wouldn’t say it’s as elaborate as John Wick, though.
What really stuck with me was the support scam scene at the beginning. The way the attacker kept answering her doubts and creating urgency felt surprisingly realistic.
Haha dude im down for some Jason Statham movies….lock stock and two smoking barrels, snatch, crank….but then you got Jason statham in the Meg. So i completely understand and im not hating at all.
Sorry bro didnt mean to hijack your post talking about Jason statham.
Haha, no worries at all! I don’t mind the Jason Statham detour!
It’s actually funny that a security discussion ended up here because of The Beekeeper.
I actually haven’t seen any of the movies you mentioned, so now you’ve given me a few Jason Statham movies to check out!