Fake AI Trading Assistant Spreads Malware Replacing Browser Wallet Extensions
A fake AI trading assistant has been spreading malware that can replace browser cryptocurrency wallet extensions on infected Windows computers, turning trusted wallet interfaces into credential traps.
The campaign, dubbed Needle Stealer, was documented by HP Wolf Security in its September threat report, which covered threats observed from April through June 2026. The attackers promoted a fake AI assistant called Tradingclaw[.]pro as an AI assistant that could follow a personalized strategy and trade around the clock.
The ZIP file presented as the software's installer contained an executable named Trading Agent.exe, a legitimate digitally signed OLE/COM Object Viewer provided by Microsoft. However, the malicious payload remained in the accompanying DLL, iviewers.dll, which was used to decrypt Needle Stealer and load it into the system.
The malware then enumerated Chromium browser extensions and checked their 32-character IDs against a hardcoded list of seven wallet extensions, including Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper. When it found a target, the malware shut down the browser and extracted a corresponding malicious extension into the existing extension folder.