The attack exploits a professionally crafted email that claims to promote a legitimate wallet solution, designed for secure staking of Cardano and participation in governance.
See also: Phishing campaign abuses Google Cloud email feature

The false announcement mentions ecosystem-related incentives, such as NIGHT and ATMA token rewards through the Diffusion Staking Basket, in order to gain credibility and attract users.
The attackers have created an almost identical announcement to the official Eternal Desktop announcement, with messages about hardware wallet compatibility, local key management, and advanced delegation checks. The email maintains a professional, polished tone with proper grammar and no obvious spelling errors, making it particularly effective in deceiving community members.
The campaign uses a newly registered domain, download.eternldesktop.network, to distribute a malicious installer without any official verification or digital signature. Independent threat researcher and malware analyst Anurag detected the malicious installer through a detailed technical examination, revealing that the seemingly legitimate Eternl.msi file contains a hidden remote administration tool, LogMeIn Resolve, which is included in the installation package.
See also: 27 malicious npm packages used as Phishing infrastructure

This discovery revealed a significant attempt to abuse the supply chain, with the aim of creating persistent unauthorized access to victims' systems.
Network analysis reveals that the malware sends system event information in JSON format to remote servers, using hardcoded API credentials, thus creating a communication channel for executing commands and monitoring the system.
Security researchers characterize this behavior as particularly critical, as remote administration tools provide attackers with the ability to remain on the system for a long time, remotely execute commands, and steal credentials after they are installed on victims' systems.
See also: Christmas online: How to protect yourself from scams and phishing this holiday season

Users should verify the authenticity of software exclusively through official channels and avoid downloading wallet apps from unverified sources or newly registered domains, no matter how professional the distribution emails appear.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
