Agentic AI Used to Trick Crypto Users into Malware
Cybercriminals are leveraging the trend of agentic AI to target cryptocurrency wallets, according to a report by HP Wolf Security.
The report highlights new techniques used by threat actors to evade detection and exploit endpoints, capitalizing on fast-changing technology trends to scale cyberattacks.
Threat actors are actively advertising fake AI trading agents to lure cryptocurrency users into downloading malware. Once installed, the malware scans the victim's browser for legitimate cryptocurrency wallet extensions, such as Coinbase and MetaMask, and replaces them with malicious lookalikes.
The rogue extensions then harvest entered credentials, granting attackers direct access to drain users' crypto assets. Patrick Schläpfer, Principal Threat Researcher at HP Security Lab, noted that cybercriminals are tapping into the rapid adoption of agentic AI tools to create convincing lures that trick users into downloading malicious software.