A sophisticated phishing campaign is targeting the Cardano community by distributing a fake "Eternl Desktop" application through convincing, professionally crafted emails. The emails, titled "Eternl Desktop Is Live – Secure Execution for Atrium & Diffusion Participants," reference legitimate Cardano ecosystem initiatives and promise enhanced security and staking features to lure high-conviction users. The installer, distributed via a suspicious domain, drops LogMeIn Resolve—a legitimate remote monitoring and management (RMM) tool—onto victims' systems, granting attackers persistent remote access while evading traditional security filters.
The campaign's use of trusted branding, ecosystem-specific incentives, and polished messaging increases its credibility and effectiveness. The installer lacks digital signature transparency and is not announced through official Eternl channels, further indicating its malicious nature. By abusing a legitimate RMM tool, attackers bypass many security controls, putting Cardano wallet holders at significant risk of system compromise and potential asset theft.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Security reporting identified suspicious domains and file hashes tied to the campaign and warned that the activity showed signs of supply-chain abuse and trojanized wallet distribution targeting cryptocurrency users.
Analysis of the fake Eternl Desktop MSI found that it silently installed LogMeIn Resolve (GoTo Resolve), a legitimate RMM tool, to give attackers persistent unattended access to victim systems and enable possible credential or wallet theft.
Attackers launched a phishing campaign aimed at the Cardano community using professionally branded emails that promoted a fake 'Eternl Desktop' wallet application and directed users to a newly registered download domain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.