Cybercriminals Create Fake AI Agents to Install Malware and Steal Cryptocurrencies
Cybercriminals use fake artificial intelligence (AI) agents to trick users into installing malware that replaces legitimate cryptocurrency wallet extensions and steals their passwords. The maneuver was detected between April and June by HP, in a scenario where agentic artificial intelligence, systems capable of performing tasks on behalf of the user, has become a new lure for financial fraud. This activity is part of HP's Threat Insights Report, which analyzed millions of devices protected by HP Wolf Security to identify recent campaigns and the methods used to evade detection systems.
How This Cyberattack That Steals Cryptocurrencies Operates
The attack presents itself as an alternative to traditional financial advisors: cybercriminals promise a tool that monitors cryptocurrency portfolios and operates automatically. The site tradingclaw posed as an AI assistant for trading digital assets, but distributed a family of malware called Needle Stealer. Once installed, the program scans browsers for wallet extensions, including Coinbase and MetaMask. When the program finds them, it replaces them with visually similar copies; by entering their login details, victims hand over their credentials to the attackers, who can access their funds. Patrick Schläpfer, a principal researcher at HP Security Lab, warned that attackers "are leveraging the adoption of agentic AI tools to develop new lures that deceive users into downloading malicious software that appears legitimate." In his view, this strategy makes the distribution of these programs "more sophisticated and harder to detect."
What Other Cyberattacks Were Identified
The second detected campaign combines Phantom Gate, a malware loader, with Phantom Stealer, a tool aimed at stealing information, including credentials and financial data. Phantom Stealer is marketed as a legitimate program for penetration testing, while Phantom Gate allows criminals to deploy and expand infection campaigns. Schläpfer stated that these tools reflect "the expansion of the threat landscape" because they enable the construction of "dangerous infection chains." The result is an increased risk of organizations being compromised. The third modality resorts to phishing, a scam that impersonates pages or services to obtain personal data, through QR codes. Victims receive PDF files with blurred content under the pretext that it was hidden "for security reasons," and they are asked to scan the code with their phone to access the information. The code redirects the user to a fraudulent page from the device. Those addresses would have been blocked when opened from a computer, but they work on phones, which have lower protection levels and expose access credentials.
How It Was Possible to Detect Different Cyberattacks
HP Wolf Security can observe these attacks because it runs suspicious programs within protected containers. This isolation allows for understanding the behavior of criminals without affecting the device. Users protected by this service opened 60 billion email attachments, web pages, and downloaded files without any security breaches being recorded. The data showed that at least 10% of the threats detected by email through HP Sure Click managed to evade one or more scanners from the email gateways. Additionally, executable files were the most frequent distribution mechanism, appearing in 40% of cases. Compressed files accounted for 38%, while PDFs reached 7.5%. James Wright, global director of Personal Systems Security at HP, noted that users "constantly move between devices and applications" through browsers and AI tools, and that criminals quickly update their tactics to follow them. Therefore, he urged organizations to adopt a zero-trust model based on isolation and containment of untrusted clicks and downloads.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Wall Street Invests Billions in Bitcoin, Individuals Hold 66% of Supply

Ledger Discovers Unauthorized Hardware Implant in User Device, CryptoBilis Halts Sales

Global Markets Focus on US September CPI Data and Waller's IMF Speech Next Week

Musk Claims Terrafab Factory Will Revolutionize Chip Manufacturing

US to Seize One Billion Dollars in Cryptocurrency Related to Iran

Central Bank Bans Online Gold and Silver Sales

Microsoft CEO Says AI Models Should Be Viewed as Internal Threats, Urges Emergency Shutdown Systems

Analysis of STRK Surge by 唐华斑竹

Analysis of Descending Triangle Pattern by Sam Price

Luxor’s reported 6–13% annualized Bitcoin yield depends on mining delivery

Coinbase’s Texas move gets a shareholder suit dismissed over Delaware-era claims

Ethereum: Vitalik Buterin entrusts his ENS to an AI agent and sets a two-year goal

Specter Questions Serpin's Token Issuance Decision, Claims Low Liquidity Damages Reputation

Triple-A Hacker Transfers 4,970 ETH to Tornado Cash, Worth Approximately $12.4 Million

White House Demands AI Companies Report Security Incidents

Inflation target of 2% may not stop the next Fed rate freeze

LONGX Launches Actively Managed Basket Product AI Nexus

Ripple co-founder donates approximately 3.6 billion yen for U.S. midterm elections amid backlash against cryptocurrency organization

MSX Daily Observation: OpenAI's Annual Revenue Reveals a $20 Billion Discrepancy! The AI Industry Chain Faces a Revenue Quality Test

Bitcoin in Russia Regulated Like Stocks: Expert Explains the Problem with Federal Law 282-FZ

Meanwhile raises 37.5 million USD for Bitcoin life insurance

NEAR Account Supports Post-Quantum ML-DSA Signature Scheme

Former FTX COO Expresses Disgust at Netflix's FTX Series Trailer

EU Targets Risks of Autonomous AI, Inspects Safety Systems of Over 30 Companies

Bitcoin Privacy Risks Highlighted by Cake Wallet COO

OpenAI, Google, Meta compete for AI domains, crypto firms target .bitcoin and .wallet

PancakeSwap pool loses 14.35 million USDT due to token permission exploit

Ostium Updates Phase Two Recovery Plan, Offering USDC Installment Payments or Equity Conversion Options

The Crucial Significance of Next Week's US CPI: Will the Fed Hold Rates Steady in October?









