Cryptelio

Hacks & Exploits

Malware Campaign Targets Crypto Wallets with Fake AI Trading Tools

Cryptelio Editorial Published 18 Sep 2026 · 10:30 UTC

HP Wolf Security has reported a concerning malware campaign that utilizes counterfeit AI crypto-trading assistants to replace legitimate browser wallet extensions on compromised Windows computers. This tactic transforms the familiar wallet interface into a credential-stealing trap.

The report, published on September 17, details how the malware, dubbed Needle Stealer, infiltrates systems after users unwittingly download a fake trading tool. This tool, promoted as an AI assistant capable of personalized trading, is distributed through search-engine poisoning and paid advertisements leading to a malicious ZIP file.

Once the ZIP file is executed, it runs a seemingly legitimate program that bypasses security checks, allowing the malware to operate undetected. The Needle Stealer then targets specific wallet extensions, including MetaMask and Coinbase Wallet, and replaces them with malicious versions that capture user credentials.

HP's findings indicate that the malware can effectively shut down browsers and extract malicious extensions into existing folders, connecting to command-and-control servers to relay stolen information. Despite the detailed analysis, the report does not disclose the scale of the operation or the number of victims affected.

New Insights on Malware Campaigns Targeting Crypto Wallets

  • Blockchain malware activity has surged by 440% due to the emergence of high-capacity open-weight AI models.
  • State-linked hackers from North Korea and Iran are responsible for approximately two-thirds of newly observed blockchain-dead-drop activity as of Q2 2026.
  • Malicious blockchain writes increased from 2.06 per day to 11.1 after the introduction of advanced AI tools.
  • North Korean-linked group UNC5342 has utilized TRON and Aptos networks for cross-chain redundancy in their malware campaigns.
  • Iranian actors have embedded command-and-control information in Bitcoin transactions directed to a historically significant address associated with Satoshi Nakamoto.
  • AI coding tools are enabling smaller operators to engage in blockchain-based command infrastructure without extensive expertise.
  • Chainalysis is now tracking blockchain-dead-drop activity across five major networks and over a dozen malware strains.
  • Cybersecurity teams can monitor blockchain transactions for signs of malware activity, leveraging the public nature of blockchain records.

FAQ

What is the Needle Stealer malware?

Needle Stealer is a malware that targets crypto wallets by replacing legitimate browser wallet extensions with counterfeit versions designed to steal user credentials.

How does the Needle Stealer malware infiltrate systems?

The malware infiltrates systems when users download a fake AI trading tool, which is distributed through search-engine poisoning and paid advertisements leading to a malicious ZIP file.

Which wallet extensions are specifically targeted by Needle Stealer?

Needle Stealer specifically targets wallet extensions such as MetaMask and Coinbase Wallet, replacing them with malicious versions.

What happens once the malware is executed?

Once executed, the malware runs a seemingly legitimate program that bypasses security checks, allowing it to operate undetected and capture user credentials.

Is there any information on the scale of the Needle Stealer operation?

The report from HP Wolf Security does not disclose the scale of the operation or the number of victims affected by the Needle Stealer malware.

Read story →