Cybercriminals Create Fake AI Agents to Install Malware and Steal Cryptocurrencies

By: www.infobae.com|2026/09/20 13:53:15

Cybercriminals use fake artificial intelligence (AI) agents to trick users into installing malware that replaces legitimate cryptocurrency wallet extensions and steals their passwords. The maneuver was detected between April and June by HP, in a scenario where agentic artificial intelligence, systems capable of performing tasks on behalf of the user, has become a new lure for financial fraud. This activity is part of HP's Threat Insights Report, which analyzed millions of devices protected by HP Wolf Security to identify recent campaigns and the methods used to evade detection systems.

How This Cyberattack That Steals Cryptocurrencies Operates

The attack presents itself as an alternative to traditional financial advisors: cybercriminals promise a tool that monitors cryptocurrency portfolios and operates automatically. The site tradingclaw posed as an AI assistant for trading digital assets, but distributed a family of malware called Needle Stealer. Once installed, the program scans browsers for wallet extensions, including Coinbase and MetaMask. When the program finds them, it replaces them with visually similar copies; by entering their login details, victims hand over their credentials to the attackers, who can access their funds. Patrick Schläpfer, a principal researcher at HP Security Lab, warned that attackers "are leveraging the adoption of agentic AI tools to develop new lures that deceive users into downloading malicious software that appears legitimate." In his view, this strategy makes the distribution of these programs "more sophisticated and harder to detect."

What Other Cyberattacks Were Identified

The second detected campaign combines Phantom Gate, a malware loader, with Phantom Stealer, a tool aimed at stealing information, including credentials and financial data. Phantom Stealer is marketed as a legitimate program for penetration testing, while Phantom Gate allows criminals to deploy and expand infection campaigns. Schläpfer stated that these tools reflect "the expansion of the threat landscape" because they enable the construction of "dangerous infection chains." The result is an increased risk of organizations being compromised. The third modality resorts to phishing, a scam that impersonates pages or services to obtain personal data, through QR codes. Victims receive PDF files with blurred content under the pretext that it was hidden "for security reasons," and they are asked to scan the code with their phone to access the information. The code redirects the user to a fraudulent page from the device. Those addresses would have been blocked when opened from a computer, but they work on phones, which have lower protection levels and expose access credentials.

How It Was Possible to Detect Different Cyberattacks

HP Wolf Security can observe these attacks because it runs suspicious programs within protected containers. This isolation allows for understanding the behavior of criminals without affecting the device. Users protected by this service opened 60 billion email attachments, web pages, and downloaded files without any security breaches being recorded. The data showed that at least 10% of the threats detected by email through HP Sure Click managed to evade one or more scanners from the email gateways. Additionally, executable files were the most frequent distribution mechanism, appearing in 40% of cases. Compressed files accounted for 38%, while PDFs reached 7.5%. James Wright, global director of Personal Systems Security at HP, noted that users "constantly move between devices and applications" through browsers and AI tools, and that criminals quickly update their tactics to follow them. Therefore, he urged organizations to adopt a zero-trust model based on isolation and containment of untrusted clicks and downloads.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com