Security professionals have alerted users to a new phishing campaign that utilizes the popularity of Pokemon and NFT to trick them into installing a remote access tool without their knowledge (RAT).
The South Korean AhnLab Security E-response Center discovered the fake Pokemon card game page (ASEC). The website reportedly provides links to buy Pokemon-branded NFTs in addition to the game itself.
According to ASEC, the “Play on PC” option on the phishing page secretly sets up a version of the well-known RAT NetSupport. The tool “was not transmitted in a manner usable for normal activities but rather in a form tailored for the threat actor to control the infected system,” according to the vendor, who labeled it “malware” read the complete article Threat Actors Spread RAT Via Pokemon NFT Card Site.
