TTO-2026-0918-139 · September 18, 2026 MalwareCryptocurrency

Needle Stealer Delivered via Fake AI Trading Agent Replaces Browser Crypto Wallet Extensions to Steal Passwords

HP Wolf Security researchNeedle Stealer malwareFake AI trading agent: tradingclaw.proSeven browser wallet extensions replacedMetaMask / Coinbase Wallet / Phantom targetedSigned Microsoft tool used for DLL side-loadingApril-June 2026 campaign

Summary

HP Wolf Security has published research documenting a campaign in which a fake AI cryptocurrency trading agent delivered Needle Stealer, malware that silently replaces legitimate browser-based cryptocurrency wallet extensions with malicious copies designed to capture wallet passwords and transmit them to attacker-controlled infrastructure. The campaign was observed between April and June 2026 and targeted users of seven browser wallet extensions including MetaMask, Coinbase Wallet, and Phantom. The initial infection vector was a counterfeit AI trading tool promoted as tradingclaw.pro. Needle Stealer used a legitimately signed Microsoft tool to load a malicious DLL, turning the wallet extensions into credential traps without breaching the wallets’ own servers or official extension code.

Timeline

DateEvent
April 2026Malwarebytes documents TradingClaw campaign; Needle Stealer circulates through multiple malware loaders including fake AI trading agent at tradingclaw.pro
April-June 2026HP Wolf Security observes Needle Stealer campaign across threat intelligence telemetry
Sep 17, 2026HP Wolf Security publishes September 2026 threat report including full Needle Stealer campaign analysis

What Happened

The campaign began with a counterfeit website at tradingclaw.pro presenting itself as an AI-powered cryptocurrency trading assistant. Users who downloaded and ran the fake tool executed a malicious installer that deployed Needle Stealer. The installer used a legitimately signed Microsoft executable to side-load a malicious DLL — leveraging the signed binary’s trusted status to load unsigned malicious code without triggering signature-based security tool alerts.

Once on a victim’s Windows system, Needle Stealer located installed browser wallet extensions and replaced them with malicious copies. The replacement extensions maintained the original wallet’s visual interface so that users continued to interact with what appeared to be their legitimate wallet. When users entered wallet passwords into the fake extension, those credentials were transmitted to attacker infrastructure. The attack did not involve a breach of Coinbase, MetaMask, Phantom, or any of the targeted wallet providers — the compromise occurred entirely on the victim’s endpoint after the counterfeit trading tool was installed.

HP Wolf Security notes that Needle Stealer also circulated through other malware loaders beyond the fake AI trading agent, indicating that tradingclaw.pro was one distribution channel within a broader malware operation. The total number of victims and losses are not known. Related campaigns documented in the same period include QR code phishing that moved victims to mobile devices, Phantom Stealer, and additional fake installer campaigns using image-based payloads, DLL side-loading, and process injection.

Note on Domain Intelligence

The attack infrastructure involved the counterfeit domain tradingclaw.pro, registered for this campaign with no legitimate business presence. Domain intelligence for the seven targeted wallet extension providers is available at warmbadge.com where those domains have been evaluated. No single victim domain is the subject of this bulletin.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 18, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026