Fake AI Trading Tool Steals Login Credentials with Needle Stealer Malware
A fake AI trading tool has been uncovered by HP Wolf Security, which promised round-the-clock automated trading but delivered malware that stole login credentials.
The tool, disguised as a legitimate Microsoft-signed executable, was promoted through a website called tradingclaw.pro and bundled with a hidden malicious file.
Once launched, the signed file quietly loaded a second component that decrypted and activated Needle Stealer, a Go-based information stealer, which targeted seven well-known wallets: MetaMask, PhantomWallet, Trust Wallet, OKX Wallet, Atomic Wallet, Tonkeeper, and Coinbase.