Fake AI Crypto Tool Replaces Browser Wallet Extensions with Malware
The HP Wolf Security threat-research team has discovered that a fake AI crypto-trading assistant distributed malware to replace browser wallet extensions on infected Windows computers. The campaign, dubbed TradingClaw, involved downloading and running a counterfeit trading tool that was promoted as an AI assistant capable of following a personalized strategy and trading around the clock.
The attackers used search-engine poisoning and paid advertisements to direct potential victims to a ZIP file presented as the software's installer. This archive contained an executable named Trading Agent.exe, which was identified by HP as OLEView, Microsoft's legitimate digitally signed OLE/COM Object Viewer. However, the malicious payload remained in the accompanying DLL.
The malware used process hollowing, a technique that runs malicious code inside a newly launched legitimate process. It enumerated Chromium browser extensions and checked their 32-character IDs against a hardcoded list covering Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper. When it found a target, the malware shut down the browser and extracted a corresponding malicious extension into the existing extension folder.