Loading prices…
🩸BEARISH

Needle Stealer Fake AI Tool Replaces 7 Crypto Wallets

The campaign targeted compromised Windows endpoints, not Coinbase, MetaMask or official extensions, while HP disclosed no victim count or aggregate loss.

HP Wolf Security found a fake AI crypto-trading assistant delivering Needle Stealer through a malicious ZIP file and replacing seven browser wallet extensions on infected Windows computers. The campaign used search-engine poisoning and paid ads to promote tradingclaw[.]pro, with the activity covered in HP's September threat report based on threats observed from April through June 2026.

Why it matters

The installer used a legitimate, digitally signed Microsoft OLEView executable to help bypass SmartScreen, while a malicious DLL loaded the stealer through process hollowing. Needle Stealer checked Chromium extension IDs for Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper.

After finding a target, the malware shut down the browser and inserted a counterfeit extension into the existing folder. The replacement connected to attacker-controlled infrastructure, loaded backup domains and displayed realistic wallet login screens designed to capture credentials. HP said the operation began with a compromised endpoint, not a breach of Coinbase, MetaMask or their official extensions.

Market impact

The campaign creates a direct security risk for users who download unverified AI trading tools, particularly when search ads make a malicious installer appear legitimate. Malwarebytes previously documented the TradingClaw campaign and linked Needle Stealer to other malware loaders, indicating that the fake assistant was one delivery route within a broader operation.

HP did not disclose a campaign-wide victim count or aggregate crypto-loss figure. Users should treat unofficial wallet software and AI trading assistants as high-risk downloads, verify extension publishers and avoid entering wallet credentials into a replacement interface on a compromised device.

Frequently asked questions

  1. How did the fake AI trading tool infect Windows computers?

    Attackers promoted tradingclaw[.]pro through search poisoning and paid ads. Victims downloaded a ZIP containing a trusted-looking OLEView executable and a malicious DLL that loaded Needle Stealer.

  2. Which wallet extensions did the malware target?

    Needle Stealer checked for Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper.

  3. How did the malware replace browser wallet extensions?

    It identified targeted Chromium extensions by their 32-character IDs, shut down the browser and inserted a malicious extension into the existing extension folder.

  4. Was Coinbase or MetaMask officially breached in this campaign?

    No. HP described the incident as a compromise of an infected Windows endpoint, not a breach of Coinbase, MetaMask or their official extensions.

  5. Did HP report how much crypto was stolen?

    No. HP did not disclose a campaign-wide victim count or aggregate crypto-loss figure.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →