Fake Trading Platform Distributes Needle Stealer Malware to Traders

Fake Trading Platform Distributes Needle Stealer Malware to Traders

First seen 26 Apr 2026, 06:15 UTC CybersecuritynewsKhaberni 78% similarity 69.0

Article Content

Browse articles
ThreatCluster

A cyber campaign has emerged involving a fraudulent trading site named 'TradingClaw', which impersonates the legitimate TradingView platform. This site entices users to download malware known as 'Needle Stealer', an advanced data-stealing tool capable of compromising browser security and stealing sensitive information, including cryptocurrency wallet data. The malware is delivered through a ZIP file that employs DLL hijacking to execute via a legitimate Windows process, evading detection. Victims are at risk of having their browsing history monitored, being redirected to malicious sites, and having their clipboard hijacked. Security researchers have noted that the attack is particularly dangerous due to the deployment of malicious browser extensions that grant attackers extensive control over the victim's browser. The campaign highlights a growing trend of using fake AI interfaces to lure users into downloading spyware. Users are advised to download software only from official sources and to regularly review their browser extensions for any unauthorized additions.

Key Points: • The fake site 'TradingClaw' masquerades as an AI trading assistant to lure victims. • Needle Stealer malware can hijack browsers and steal sensitive data, including cryptocurrency wallets. • Users are urged to verify software sources and monitor browser extensions to prevent infection.

ThreatCluster AI How this analysis works

Timeline

2026-04-23
Cybersecuritynews reports on the fake TradingClaw site.
2026-04-26
Khaberni publishes detailed analysis of the Needle Stealer malware.

Community

Browse all →

Tracked Entities in This Story