HP Wolf Security’s September 2026 Threats Insight Report exposed a campaign that used a fake AI crypto-trading agent as a lure to distribute the Needle Stealer malware. Between April and June 2026, attackers promoted a website at tradingclaw[.]pro offering an always-on AI trading product. Visitors were directed to download a Windows executable presented as Microsoft-signed, a tactic designed to bypass SmartScreen reputation checks and appear trustworthy.
After execution, the malware leveraged a Microsoft-signed OLEView executable for DLL side-loading, causing a legitimate program to load a malicious dynamic-link library. The infection chain replaced legitimate browser-wallet extension files with malicious copies, then displayed counterfeit wallet interfaces that captured passwords and sent them to an attacker-controlled server.
The operation targeted seven browser-wallet extensions: MetaMask, Coinbase Wallet, Phantom, Trust Wallet, OKX Wallet, Atomic Wallet and Tonkeeper. HP said the common element was the browser extension rather than any single blockchain or trading venue. No figures for affected users, losses or stolen data were provided in the report.
HP noted that criminals are leaning into interest around agentic AI to steal crypto-wallet credentials. The fake website borrowed the look of a trusted AI tool, while the reported Microsoft signature was part of the delivery chain rather than proof that the download was safe.