Trump Cryptocurrency Delivers ConnectWise RAT
Essential information
- Published
- 11/03/2025 17:34
- Modified
- 11/03/2025 18:53
- Tags
- 2025-03-11 binance impersonation connectwise rat cryptocurrency scam password theft phishing remote access trojan social engineering
- Related entities
- 1 observables, 10 techniques (mitre), 1 malware
Description
An email campaign impersonating Binance is offering fake TRUMP coins to lure victims into downloading a malicious 'Binance Desktop' application, which actually installs ConnectWise RAT. The attackers have created a convincing web page mimicking Binance's interface to host the malware download. Once infected, threat actors quickly establish remote control of the victim's computer, targeting saved passwords in applications like Microsoft Edge. The campaign employs sophisticated social engineering tactics, including sender name spoofing and risk warnings, to appear legitimate. Threat actors are actively monitoring infections and can connect to compromised systems within minutes of installation.