Helpnetsecurity Cybercriminals Use Fake AI Agents to Steal Crypto Wallets
Article Content
- •Fake AI trading agents are being used to distribute malware targeting crypto wallets.
- •Needle Stealer malware replaces legitimate browser extensions to harvest user credentials.
- •QR code phishing tactics are redirecting users to less secure mobile environments.
Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were identified between April and June 2026, targeting users of seven specific browser wallet extensions. Additionally, QR code phishing tactics are being employed to redirect victims to less secure mobile environments. HP's Threat Insights Report highlights the growing sophistication of these attacks, including the use of a new malware loader called Phantom Gate. The current status indicates ongoing campaigns with significant risk to crypto users. Organizations are urged to remain vigilant and implement security measures to protect against these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track FormBook and CVE-2026-90894 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…