{
  "metadata": {
    "generator": "Bulwark Black IOC Extractor",
    "source": "https://bulwarkblack.com/physical-mail-phishing-targets-trezor-and-ledger-users-attackers-use-qr-codes-to-steal-recovery-phrases/",
    "fang": "live",
    "exported_at": "2026-08-27T00:00:00Z",
    "total": 7,
    "categories": 2,
    "migration_policy": "typed-only-better-v2"
  },
  "iocs": {
    "Domains": [
      "authentication-check.io",
      "ledger.setuptransactioncheck.com",
      "setuptransactioncheck.com",
      "trezor.authentication-check.io"
    ],
    "URLs": [
      "https://ledger.setuptransactioncheck.com/",
      "https://trezor.authentication-check.io/",
      "https://trezor.authentication-check.io/black/api/send.php"
    ]
  }
}