Fake AI Trading Agent Distributes Needle Stealer Malware to Hijack Crypto Wallets
Attackers are using a convincing fake AI crypto trading agent website to distribute Needle Stealer malware, which replaces users' browser wallets to steal their passwords and access funds.

Cybercriminals have launched a sophisticated campaign leveraging a fake AI crypto trading agent website to distribute the Needle Stealer malware. This malicious software is designed to replace a victim's legitimate browser wallet extension with a compromised version, ultimately stealing their wallet password and granting attackers access to their cryptocurrency.
The campaign, observed by HP between April and June 2026, specifically targeted users of seven popular browser wallet extensions, including MetaMask, Coinbase Wallet, and Phantom. Attackers lured victims by making the fake trading agent appear prominently in search results and advertisements, preying on the growing interest in AI-driven trading tools.
The deceptive website, tradingclaw[.]pro, presented a convincing facade, naming its AI agent to echo well-known AI assistants and promising round-the-clock crypto trading capabilities. Crucially, the downloaded installer, "Trading Agent.exe," was a genuine Microsoft-signed program known as OLEView. This allowed it to bypass Windows SmartScreen's reputation checks, a common security measure designed to protect users from malicious software.
Once executed, the OLEView program loads a malicious DLL file, "iviewers.dll," through a technique known as DLL side-loading. This DLL then injects the Needle Stealer malware into a legitimate running process using process hollowing. The stealer actively searches for the targeted wallet extensions, terminates the browser, and then unpacks a malicious replica of the wallet extension into the browser's extension directory.
The compromised wallet extension then establishes communication with the attacker's command server, transmitting any password the victim enters to unlock their wallet. With both the wallet ID and the password in hand, the threat actors gain full control over the victim's digital assets.
HP researchers also noted that the campaign employed QR code phishing, or "quishing," to redirect victims to their mobile devices. This tactic exploits the fact that mobile devices often have fewer security defenses compared to work PCs, allowing malicious links that might be blocked on a desktop to be successfully delivered and executed on a phone.
This incident highlights a growing trend where attackers are exploiting the hype around AI and the increasing adoption of cryptocurrency wallets to deploy highly effective malware. The use of legitimate-signed binaries and advanced injection techniques demonstrates a significant evolution in threat actor capabilities, underscoring the need for enhanced vigilance and security practices among cryptocurrency users.