Phishing Campaign Targets MetaMask Users With Fake Security Reports To Bypass Filters

Security researchers are warning cryptocurrency users after a new phishing campaign began targeting MetaMask users. The attackers are sending convincing emails that aim to frighten victims into securing their accounts. However, the real goal is to steal credentials.

MetaMask is a widely used crypto wallet available as a browser extension and mobile application. Because it directly controls digital assets, it has become a frequent target for financially motivated cybercriminals.

This latest campaign stands out because the attackers combine social engineering with a harmless-looking document designed to bypass security filters.

Fake Incident Report As A Lure

The phishing email claims the user must enable two-factor authentication (2FA) after suspicious login activity.

At first glance, the message appears like a legitimate security alert. The attackers rely on urgency and fear a classic social engineering technique to push victims into acting quickly.

Inside the email is a PDF attachment named “Security_Reports.pdf.” The document appears to be a security incident report detailing unusual access to the victim’s account.

Fake Security Reports Target MetaMask (Source: sans)
Fake Security Reports Target MetaMask (Source: sans)

Its purpose is psychological: convince the recipient that their wallet is under attack so they will follow the instructions.

Interestingly, the PDF itself contains no malware. Technical analysis shows it was generated using the ReportLab PDF library, a legitimate document-creation tool commonly used by developers.

Metadata reveals anonymous authorship and timestamps for automated generation. The file’s SHA-256 hash is:

2486253ddc186e9f4a061670765ad0730c8945164a3fc83d7b22963950d6dcd1

The attackers use this clean document to avoid antivirus detection. Since it is not malicious code, email gateways are less likely to block it.

The email then directs victims to a fake verification page hosted on cloud infrastructure:

hxxps://access-authority-2fa7abff0e[.]s3.us-east-1[.]amazonaws[.]com/index.html

Hosting the page on a trusted cloud provider increases credibility and helps bypass reputation-based filtering systems.

Credential Harvesting Attempt

When victims click the link, they are asked to “enable 2FA.” Instead of improving security, the page captures wallet credentials or recovery phrases.

Once attackers obtain this information, they can immediately access the wallet and transfer cryptocurrency, which is typically irreversible.

Fake Security Reports Target MetaMask (Source: sans)
Fake Security Reports Target MetaMask (Source: sans)

The campaign demonstrates a growing phishing trend: attackers are shifting from malicious attachments to convincing documentation. By delivering a non-malicious PDF, they evade security scanning while still manipulating human behavior.

Despite the creativity, the campaign shows some weaknesses. The sender address is not spoofed, and the PDF is not personalized with the victim’s email address.

However, many users may still trust the message because of the realistic incident report and urgency.

IndicatorTypeDescription
hxxps://access-authority-2fa7abff0e[.]s3[.]us-east-1[.]amazonaws[.]com/index.htmlURLPhishing landing page hosted on AWS S3.
2486253ddc186e9f4a061670765ad0730c8945164a3fc83d7b22963950d6dcd1SHA256Hash of “Security_Reports.pdf” attachment.
Security_Reports.pdfFilenameCommon attachment in this campaign.
ReportLab PDF LibraryMetadataProducer string indicating generation tool.

According to Sans, security experts advise users not to click login links in email alerts. Instead, they should manually open the official wallet website or application.

Enabling real two-factor authentication inside the legitimate app not through email links remains the safest defense.

Ultimately, the attack highlights a key cybersecurity lesson: phishing succeeds not through malware, but through psychology.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories