Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Malware disguised as AI crypto trading software targets browser wallet extensions
00

Malware disguised as AI crypto trading software targets browser wallet extensions

Sep 18, 2026

HP Wolf Security reports that a cybercriminal campaign active from April to June 2026 distributed Needle Stealer malware disguised as an AI crypto trading assistant. The malware exploits Microsoft's legitimate, digitally signed OLEView tool to bypass security checks before replacing seven popular browser wallet extensions—including MetaMask, Coinbase Wallet, and Phantom—with credential-stealing clones. The attack targets individual endpoints rather than breaching the wallet services directly.

TradingClaw malware campaign

  • ▪HP Wolf Security's September 2026 threat report revealed a cybercriminal campaign active from April to June 2026 that distributed malware disguised as an AI-powered crypto trading assistant.
  • ▪Cybercriminals promoted a fake AI trading assistant on the website tradingclaw[.]pro using search-engine poisoning and paid advertisements to lure users seeking automated trading tools
  • ▪Malwarebytes documented the TradingClaw campaign in April 2026, finding that the Needle Stealer malware also circulated through other, unspecified malware loaders

Needle Stealer wallet-replacement mechanism

  • ▪A malicious replacement wallet extension installed by Needle Stealer malware displays realistic login screens to capture the user's password and wallet identifying information, sending them to an attacker-controlled server
  • ▪The Needle Stealer malware scans Chromium browser extensions and compares their 32-character IDs against a hardcoded list of targeted cryptocurrency wallets.
  • ▪Upon finding a targeted extension, Needle Stealer shuts down the victim's browser and replaces the genuine extension with a malicious copy in the browser's extension folder

Targeted browser wallet extensions

  • ▪The targeted list of browser wallet extensions also included Trust Wallet, Atomic Wallet, OKX Wallet, and Tonkeeper.
  • ▪The Needle Stealer malware campaign, active from April to June 2026, targeted seven specific browser wallet extensions, including MetaMask, Coinbase Wallet, and Phantom
  • ▪HP Wolf Security reported that the Needle Stealer campaign, active from April to June 2026, compromised individual user endpoints rather than breaching the official systems of Coinbase, MetaMask, or their official extensions

Microsoft-signed software exploitation

  • ▪The malicious installation package included Microsoft's legitimate, digitally signed OLEView software (Trading Agent.exe) to bypass Microsoft's SmartScreen reputation checks.
  • ▪Running the trusted Microsoft-signed program caused it to load a malicious accompanying DLL file named iviewers.dll, which decrypted Needle Stealer using process hollowing.

2 sources

Cryptoslate
Fake AI crypto software is secretly replacing browser wallet extensions
View source article
Ambcrypto
Fake AI trading agent replaces crypto wallets to steal passwords - AMBCrypto
View source article

Featured stories

View more in AI misinformation & deepfakes

White House launches America.gov AI chatbot to help navigate government services

Sep 29, 2026 · 7 sources

YouTube and Meta reverse ad bans for Alex Gibney Musk documentary after backlash

Sep 26, 2026 · 2 sources

Story comments

Loading comments…

Related entities

MetaMask

Related Projects

MicrosoftCoinbase Wallet

Topics

AI misinformation & deepfakesCrypto privacy & surveillanceCrypto security

Featured stories

View more in AI misinformation & deepfakes

White House launches America.gov AI chatbot to help navigate government services

Sep 29, 2026 · 7 sources

YouTube and Meta reverse ad bans for Alex Gibney Musk documentary after backlash

Sep 26, 2026 · 2 sources