Microsoft-Signed Binary Used in Malware Attack
Cybercriminals are exploiting interest in agentic AI to convince users to install malware. HP uncovered a campaign that used a legitimate Microsoft-signed Windows binary, OLEView, to help deliver an information stealer called Needle Stealer.
The attackers posed as an AI-powered cryptocurrency trading assistant and promised users a personalized bot capable of following their investment strategies and trading around the clock.
However, rather than providing an AI trading agent, the site delivered Needle Stealer, which was designed to target cryptocurrency wallets stored through browser extensions.