HP Wolf Security reports that a cybercriminal campaign active from April to June 2026 distributed Needle Stealer malware disguised as an AI crypto trading assistant. The malware exploits Microsoft's legitimate, digitally signed OLEView tool to bypass security checks before replacing seven popular browser wallet extensions—including MetaMask, Coinbase Wallet, and Phantom—with credential-stealing clones. The attack targets individual endpoints rather than breaching the wallet services directly.
TradingClaw malware campaign
- ▪HP Wolf Security's September 2026 threat report revealed a cybercriminal campaign active from April to June 2026 that distributed malware disguised as an AI-powered crypto trading assistant.
- ▪Cybercriminals promoted a fake AI trading assistant on the website tradingclaw[.]pro using search-engine poisoning and paid advertisements to lure users seeking automated trading tools
- ▪Malwarebytes documented the TradingClaw campaign in April 2026, finding that the Needle Stealer malware also circulated through other, unspecified malware loaders
Needle Stealer wallet-replacement mechanism
- ▪A malicious replacement wallet extension installed by Needle Stealer malware displays realistic login screens to capture the user's password and wallet identifying information, sending them to an attacker-controlled server
- ▪The Needle Stealer malware scans Chromium browser extensions and compares their 32-character IDs against a hardcoded list of targeted cryptocurrency wallets.
- ▪Upon finding a targeted extension, Needle Stealer shuts down the victim's browser and replaces the genuine extension with a malicious copy in the browser's extension folder
Targeted browser wallet extensions
- ▪The targeted list of browser wallet extensions also included Trust Wallet, Atomic Wallet, OKX Wallet, and Tonkeeper.
- ▪The Needle Stealer malware campaign, active from April to June 2026, targeted seven specific browser wallet extensions, including MetaMask, Coinbase Wallet, and Phantom
- ▪HP Wolf Security reported that the Needle Stealer campaign, active from April to June 2026, compromised individual user endpoints rather than breaching the official systems of Coinbase, MetaMask, or their official extensions
Microsoft-signed software exploitation
- ▪The malicious installation package included Microsoft's legitimate, digitally signed OLEView software (Trading Agent.exe) to bypass Microsoft's SmartScreen reputation checks.
- ▪Running the trusted Microsoft-signed program caused it to load a malicious accompanying DLL file named iviewers.dll, which decrypted Needle Stealer using process hollowing.
Story comments
Loading comments…