Suspected Phishing Campaign Targets Cardano Users Through Fake “Eternl Desktop” Announcement

A sophisticated phishing campaign has emerged within the Cardano ecosystem, distributing a fake version of the popular Eternl wallet under the guise of a new desktop release.

The fraudulent email, titled “Eternl Desktop Is Live Secure Execution for Atrium & Diffusion Participants,” has been circulating since late December and is designed to appear authentic, targeting community members involved in staking and governance activities.

Deceptive Messaging and Social Engineering

The email’s content is crafted with close attention to detail, aligning with Cardano’s governance narrative and emphasizing security, decentralization, and user empowerment.

It strategically references legitimate ecosystem terms such as Atrium and Diffusion Staking Basket, while promising NIGHT and ATMA token rewards to entice recipients to download the purported application.

The message also highlights “local-first, non-browser signing,” positioning it as a safer alternative to browser-based wallets.

Fake Eternl Desktop phishing scam
Fake Eternl Desktop phishing scam

Its design, formatting, and flawless grammar contribute to its credibility, creating an illusion of professionalism.

The final line, “Eternl Desktop is where Cardano decisions are finalized,” serves as a strong call to action, instilling urgency and importance.

However, the download link provided (hxxps://download[.]eternldesktop[.]network) points to a newly registered, unverified domain not associated with the official Eternl project.

The file is distributed as a standalone MSI installer with no digital signature, checksum, or release documentation, making it impossible to verify authenticity before installation.

Malicious Installer Behavior and Risk Assessment

Technical analysis of the downloaded file, named Eternl.msi (23.3MB), reveals that it embeds a remote monitoring and management (RMM) tool disguised as wallet software.

Upon extraction, the contained executable, unattended-updater.exe, was identified as LogMeIn GoTo Resolve Unattended, a legitimate enterprise application repurposed for unauthorized access.

Once executed, the installer creates a folder under C:\Program Files (x86)\GoTo Resolve Unattended and deploys configuration files, including unattended.json, which enables remote connectivity to the system without the user’s knowledge or consent.

During dynamic analysis, the program attempted multiple outbound connections to domains such as dumpster.console.gotoresolve.com and zerotrust.services.gotoresolve.com to transfer event data and system information.

Although GoTo Resolve is a legitimate remote support product, its inclusion in a fake wallet installer constitutes clear malicious abuse.

Security researchers have flagged the file as PUA or Riskware, indicating behavior consistent with post-compromise persistence and remote command execution commonly seen in cryptocurrency-targeted attacks.

Experts warn users not to download or install any software from unverified domains and to rely solely on official Eternl or Cardano communication channels for wallet updates or releases.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories