diff --git a/indicators/crypto-eternldesktop-network-logmein-rmm.yml b/indicators/crypto-eternldesktop-network-logmein-rmm.yml new file mode 100644 index 00000000..31c47343 --- /dev/null +++ b/indicators/crypto-eternldesktop-network-logmein-rmm.yml @@ -0,0 +1,26 @@ +title: eternl desktop site drops LogMeIn RMM +description: | + RMM Abuse in a Crypto Wallet Distribution Campaign. It drops RMM LogMeIn Resolve (Go To Resolve) from download.eternldesktop.network site +level: potentially_malicious +references: + - https://x.com/Malwarehunterr/status/2006107427868135804?s=20 + - https://urlscan.io/result/019b7a53-82a5-75b5-a372-131336a7b408/#summary + +detection: + eternaldesktopTitle: + title: + - "Eternl Desktop - Secure Cardano Execution, Reimagined" + + etrnlHTMLFragments: + html|contains|all: + - '
© 2025 Eternl. All rights reserved.
' + - '