Fake Trading Platform Distributes Needle Stealer Malware to Traders
Article Content
- •The fake site 'TradingClaw' masquerades as an AI trading assistant to lure victims.
- •Needle Stealer malware can hijack browsers and steal sensitive data, including cryptocurrency wallets.
- •Users are urged to verify software sources and monitor browser extensions to prevent infection.
A cyber campaign has emerged involving a fraudulent trading site named 'TradingClaw', which impersonates the legitimate TradingView platform. This site entices users to download malware known as 'Needle Stealer', an advanced data-stealing tool capable of compromising browser security and stealing sensitive information, including cryptocurrency wallet data. The malware is delivered through a ZIP file that employs DLL hijacking to execute via a legitimate Windows process, evading detection. Victims are at risk of having their browsing history monitored, being redirected to malicious sites, and having their clipboard hijacked. Security researchers have noted that the attack is particularly dangerous due to the deployment of malicious browser extensions that grant attackers extensive control over the victim's browser. The campaign highlights a growing trend of using fake AI interfaces to lure users into downloading spyware. Users are advised to download software only from official sources and to regularly review their browser extensions for any unauthorized additions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Needle Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cybercriminals Use Fake AI Agents to Steal Crypto Wallets Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…