A detailed investigation into a phishing attack targeting Web3 wallets, uncovering tactics and delivery methods.
In the dynamic and ever-evolving world of security/">cryptocurrency, security remains a paramount concern. Recently, the SlowMist security team identified an elaborate phishing attack that exploited the trust of Web3 wallet users. This attack spanned several months and utilized various communication channels to impersonate popular wallet brands, including Keystone and OneKey.
The phishing operation commenced with two deceiving emails that claimed to be legitimate updates from these wallets. The attackers utilized enticing pretexts such as "terms of service updates" and "account verification" to coerce recipients into taking urgent actions. The emails directed victims to counterfeit pages that mimicked DocuSign, enticing them to download a rogue application masquerading as a legitimate signing tool.
A thorough analysis of this phishing campaign revealed its multifaceted nature. Attackers did not limit themselves to single-brand impersonation; rather, they registered an array of domains, created numerous repositories on GitHub with wallet names, and repurposed various file formats to deliver malicious payloads. Each file ultimately perfected the same malicious goal: installing remote management software to establish a foothold on victims' computers.
The phishers' choice of bait—"compliance notices"—represents a marked departure from common phishing lures, such as promises of airdrops or contest wins. By invoking topics related to compliance, regulation, and account verification, attackers aimed to reduce skepticism among their targets.
For instance, one phishing email targeting Keystone users bore the subject line, "Your Keystone Nexus Account: Terms Update Required." In this correspondence, purported changes aligned with European Union regulations were highlighted, pushing victims to either schedule a brief explanatory meeting or to download materials for immediate review via DocuSign. The hidden danger lurked in the second action option, leading users to a malicious download.
Similarly, the phishers leveraged the OneKey brand by claiming the need for KYC updates due to business expansions, citing prominent investors. Both emails set strict deadlines and threatened account restrictions for non-compliance, thereby instilling urgency with fabricated compliance mandates.
The phishing attack's infrastructure consisted of several domains, including onekeynewsletter.org and keystonepolicyreview.org, which were implicated in distributing phishing emails and hosting counterfeit pages. While these domains presented as distinct entities, their close registration timings as well as functional roles strongly suggested they were orchestrated by the same actor or group.
In-depth investigation uncovered four major domains that linked to the phishing campaign: onekeynewsletter.org, onekeypolicyreview.org, keystonepolicyreview.org, and keystnews.com. Registered within an 11-day window in July 2026, these domains exhibited consistent naming patterns, indicating they were likely part of a coordinated effort to mislead users.
As for the delivery of malicious payloads, the attackers employed several formats, including VBS, BAT, and EXE files. Each delivery method aimed to achieve the same malicious action: the installation of remote control software on victims’ machines. For instance, a VBS file crafted for the Keystone phishing scam first escalated privileges before deploying a rogue MSI installation package under the guise of the DocuSign installation.
Surprisingly, the attackers used GitHub to expand their distribution toolset. They created repositories under the account name appInstallercloud, ostensibly uploading installation files associated with various wallet services. These repositories included named files that suggested legitimacy, but they contained identical hashes, indicating a recycling of the same malicious components across different brands.
This tactic offered the attackers resilience: should their phishing pages go down, they retained alternate download locations on GitHub, allowing them to quickly pivot and continue their campaign. By creating these public repositories, which appeared harmless on the surface, attackers ensured a wider reach and more effective means of delivering their payloads.
The ramifications of such phishing attacks extend beyond mere theft of credentials. Once established, the remote control software grants attackers a window into a victim’s digital life. They can potentially access sensitive information, including wallet applications, browser extensions, and trading accounts, posing severe risks to the crypto assets of individuals and organizations alike.
MistEye, the threat monitoring platform developed by SlowMist, demonstrated its ability to respond to these risks through proactive alerts and dynamic security monitoring. The integration of intelligence into risk management processes allows for near real-time warnings about malicious activities connected to phishing operations.
For individual users, the key takeaway is to exercise vigilance and verify any unusual requests for software downloads, especially if such requests come via email. Always navigate to the official websites to authenticate such claims rather than relying solely on the information presented in the message.
For businesses and security teams, it is crucial to adopt an extensive security posture, not just focusing on blocking phishing domains. Continuous monitoring for the installation of suspicious applications, specifically looking for unusual ScreenConnect services alongside LSA Authentication Packages and SafeBoot entries, is imperative. Following suspicious activity, securing sensitive account credentials is necessary, considering the possibility that endpoints may be compromised.
The obscure nature of phishing schemes illustrates the complexity of current threats in the digital landscape, especially in Web3. Attackers continuously adapt their strategies, emphasizing the importance of collective vigilance by users, enterprises, and security teams alike. Attacks disguised as compliance notices and official communications create a challenging environment where discerning real threats from legitimate operations becomes critical.
As fraudsters increasingly refine their approaches, this type of social engineering demands a proactive stance: educating users, employing advanced threat intelligence, and maintaining constant vigilance can significantly diminish the chances of falling victim to such sophisticated phishing attacks.
What is a phishing attack?
Phishing is a type of cyberattack where attackers impersonate legitimate entities to trick users into revealing sensitive information, usually through deceptive emails or websites.
How can I protect myself from phishing attacks?
To safeguard against phishing, verify email senders, avoid clicking on suspicious links, and use multi-factor authentication to secure accounts.
What should I do if I suspect I've been phished?
If you suspect phishing, immediately change your passwords, enable security alerts, and report the incident to your organization or security team.