216.73.216.6

Trump Cryptocurrency Delivers ConnectWise RAT

· Published 11/03/2025 17:34 · Modified 11/03/2025 18:53

Export JSON

Essential information

Published
11/03/2025 17:34
Modified
11/03/2025 18:53
Tags
2025-03-11 binance impersonation connectwise rat cryptocurrency scam password theft phishing remote access trojan social engineering
Related entities
1 observables, 10 techniques (mitre), 1 malware

Description

An email campaign impersonating Binance is offering fake TRUMP coins to lure victims into downloading a malicious 'Binance Desktop' application, which actually installs . The attackers have created a convincing web page mimicking Binance's interface to host the malware download. Once infected, threat actors quickly establish remote control of the victim's computer, targeting saved passwords in applications like Microsoft Edge. The campaign employs sophisticated tactics, including sender name spoofing and risk warnings, to appear legitimate. Threat actors are actively monitoring infections and can connect to compromised systems within minutes of installation.

External references