Security researchers are warning cryptocurrency users after a new phishing campaign began targeting MetaMask users. The attackers are sending convincing emails that aim to frighten victims into securing their accounts. However, the real goal is to steal credentials.
MetaMask is a widely used crypto wallet available as a browser extension and mobile application. Because it directly controls digital assets, it has become a frequent target for financially motivated cybercriminals.
This latest campaign stands out because the attackers combine social engineering with a harmless-looking document designed to bypass security filters.
Fake Incident Report As A Lure
The phishing email claims the user must enable two-factor authentication (2FA) after suspicious login activity.
At first glance, the message appears like a legitimate security alert. The attackers rely on urgency and fear a classic social engineering technique to push victims into acting quickly.
Inside the email is a PDF attachment named “Security_Reports.pdf.” The document appears to be a security incident report detailing unusual access to the victim’s account.

Its purpose is psychological: convince the recipient that their wallet is under attack so they will follow the instructions.
Interestingly, the PDF itself contains no malware. Technical analysis shows it was generated using the ReportLab PDF library, a legitimate document-creation tool commonly used by developers.
Metadata reveals anonymous authorship and timestamps for automated generation. The file’s SHA-256 hash is:
2486253ddc186e9f4a061670765ad0730c8945164a3fc83d7b22963950d6dcd1
The attackers use this clean document to avoid antivirus detection. Since it is not malicious code, email gateways are less likely to block it.
The email then directs victims to a fake verification page hosted on cloud infrastructure:
hxxps://access-authority-2fa7abff0e[.]s3.us-east-1[.]amazonaws[.]com/index.html
Hosting the page on a trusted cloud provider increases credibility and helps bypass reputation-based filtering systems.
Credential Harvesting Attempt
When victims click the link, they are asked to “enable 2FA.” Instead of improving security, the page captures wallet credentials or recovery phrases.
Once attackers obtain this information, they can immediately access the wallet and transfer cryptocurrency, which is typically irreversible.

The campaign demonstrates a growing phishing trend: attackers are shifting from malicious attachments to convincing documentation. By delivering a non-malicious PDF, they evade security scanning while still manipulating human behavior.
Despite the creativity, the campaign shows some weaknesses. The sender address is not spoofed, and the PDF is not personalized with the victim’s email address.
However, many users may still trust the message because of the realistic incident report and urgency.
| Indicator | Type | Description |
|---|---|---|
| hxxps://access-authority-2fa7abff0e[.]s3[.]us-east-1[.]amazonaws[.]com/index.html | URL | Phishing landing page hosted on AWS S3. |
| 2486253ddc186e9f4a061670765ad0730c8945164a3fc83d7b22963950d6dcd1 | SHA256 | Hash of “Security_Reports.pdf” attachment. |
| Security_Reports.pdf | Filename | Common attachment in this campaign. |
| ReportLab PDF Library | Metadata | Producer string indicating generation tool. |
According to Sans, security experts advise users not to click login links in email alerts. Instead, they should manually open the official wallet website or application.
Enabling real two-factor authentication inside the legitimate app not through email links remains the safest defense.
Ultimately, the attack highlights a key cybersecurity lesson: phishing succeeds not through malware, but through psychology.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.