Agentic AI Used to Lure Crypto Users into Malware Trap
Cybercriminals are increasingly using Agentic AI momentum to trick users into downloading malware that steals their cryptocurrency wallets, according to HP's latest Threat Insights Report.
The report reveals that attackers are capitalizing on interest in Agentic AI by creating fake AI trading agents to dupe crypto users into downloading malicious software. Once downloaded, the malware replaces trusted browser extensions with malicious versions that harvest credentials entered by victims.
This tactic makes malware delivery more polished and harder to detect, making it easier for attackers to steal crypto holdings. HP researchers also identified a new malware loader called Phantom Gate, which appears to extend the Phantom Stealer campaign. This combination of Phantom Stealer malware and the Phantom Gate loader mechanism enables threat actors to easily compose dangerous infection chains.
Patrick Schläpfer, Principal Threat Researcher at HP Security Lab, comments that attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software. This tactic greatly increases the risk of compromise for organizations.