Threat actors used punycode and other lookalike domains to impersonate Ledger and target cryptocurrency users after the company's customer data breach became public. Proofpoint reported thousands of phishing emails directing victims to a spoofed Ledger site that offered trojanized Ledger Live installers for Windows, macOS, and Linux. The altered application removed normal setup options, coerced users into entering wallet recovery phrases, validated the words against the BIP-39 mnemonic list, and exfiltrated completed seed phrases over HTTP, enabling theft of associated cryptocurrency. A parallel campaign used fake Ledger web pages, likely distributed by SMS, to steal recovery phrases without requiring a download.
Separate infrastructure analysis tied Ledger-themed domains to a broader homograph-domain operation that also impersonated Brave, Signal, and Telegram through internationalized domain names encoded with the xn-- Punycode prefix. Silent Push identified domains such as xn--brav-yva[.]com, promoted through Google ads, that delivered ISO files linked to the RedLine infostealer, and said the registrations and hosting overlapped with other brand-impersonation activity. Together, the reporting shows attackers combining breach-themed social engineering, IDN spoofing, and malware delivery to compromise cryptocurrency holders and steal credentials or wallet access without attacking Ledger hardware directly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The domain xn--brav-yva[.]com, impersonating Brave as bravė[.]com, was registered through NameCheap. Silent Push linked it to a broader cluster of punycode lookalike domains impersonating brands including Ledger, Signal, and Telegram.
By this point, the same actor had launched a second campaign that stole Ledger recovery phrases through a web flow rather than a malicious application. The landing pages, likely distributed by SMS, guided victims through fake wallet connection steps before collecting mnemonic words.
Proofpoint discovered several thousand phishing emails impersonating Ledger that claimed users’ assets were at risk and directed recipients to a spoofed Ledger Live download page. The campaign used a punycode lookalike domain and offered trojanized installers for Windows, macOS, and Linux.
Ledger disclosed a breach involving 9,500 customers’ names and contact information. The company warned users to watch for phishing attempts and said it would never ask for the 24 words of a recovery phrase.
A Brave security engineer reported an impersonating domain promoted through Google ads. Silent Push found the site delivered an ISO installer that appeared to contain the RedLine infostealer and tied it to related homoglyph infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcesilentpush.com
Open sourceproofpoint.com
Open sourceen.wikipedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.