ANNOUNCEMENT
Expose Web3 Phishing Ring Using Fake Compliance Emails
SlowMist captured a months-long phishing campaign impersonating Keystone and OneKey. Attackers used compliance-themed emails with fake DocuSign pages to trick victims into downloading remote management software. Four domains, registered July 2026, were linked. Remote control client connected to alberthumanclinic.com, port 8041. MistEye pushed risk alerts.
