Cybercriminals Create Fake AI Agents to Install Malware and Steal Cryptocurrencies
Cybercriminals use fake artificial intelligence (AI) agents to trick users into installing malware that replaces legitimate cryptocurrency wallet extensions and steals their passwords. The maneuver was detected between April and June by HP, in a scenario where agentic artificial intelligence, systems capable of performing tasks on behalf of the user, has become a new lure for financial fraud. This activity is part of HP's Threat Insights Report, which analyzed millions of devices protected by HP Wolf Security to identify recent campaigns and the methods used to evade detection systems.
How This Cyberattack That Steals Cryptocurrencies Operates
The attack presents itself as an alternative to traditional financial advisors: cybercriminals promise a tool that monitors cryptocurrency portfolios and operates automatically. The site tradingclaw posed as an AI assistant for trading digital assets, but distributed a family of malware called Needle Stealer. Once installed, the program scans browsers for wallet extensions, including Coinbase and MetaMask. When the program finds them, it replaces them with visually similar copies; by entering their login details, victims hand over their credentials to the attackers, who can access their funds. Patrick Schläpfer, a principal researcher at HP Security Lab, warned that attackers "are leveraging the adoption of agentic AI tools to develop new lures that deceive users into downloading malicious software that appears legitimate." In his view, this strategy makes the distribution of these programs "more sophisticated and harder to detect."
What Other Cyberattacks Were Identified
The second detected campaign combines Phantom Gate, a malware loader, with Phantom Stealer, a tool aimed at stealing information, including credentials and financial data. Phantom Stealer is marketed as a legitimate program for penetration testing, while Phantom Gate allows criminals to deploy and expand infection campaigns. Schläpfer stated that these tools reflect "the expansion of the threat landscape" because they enable the construction of "dangerous infection chains." The result is an increased risk of organizations being compromised. The third modality resorts to phishing, a scam that impersonates pages or services to obtain personal data, through QR codes. Victims receive PDF files with blurred content under the pretext that it was hidden "for security reasons," and they are asked to scan the code with their phone to access the information. The code redirects the user to a fraudulent page from the device. Those addresses would have been blocked when opened from a computer, but they work on phones, which have lower protection levels and expose access credentials.
How It Was Possible to Detect Different Cyberattacks
HP Wolf Security can observe these attacks because it runs suspicious programs within protected containers. This isolation allows for understanding the behavior of criminals without affecting the device. Users protected by this service opened 60 billion email attachments, web pages, and downloaded files without any security breaches being recorded. The data showed that at least 10% of the threats detected by email through HP Sure Click managed to evade one or more scanners from the email gateways. Additionally, executable files were the most frequent distribution mechanism, appearing in 40% of cases. Compressed files accounted for 38%, while PDFs reached 7.5%. James Wright, global director of Personal Systems Security at HP, noted that users "constantly move between devices and applications" through browsers and AI tools, and that criminals quickly update their tactics to follow them. Therefore, he urged organizations to adopt a zero-trust model based on isolation and containment of untrusted clicks and downloads.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Toyosa adds BTC alongside USDT for Toyota purchases

Bitcoin: VanEck Criticizes Metaplanet's Compensation Model

Ethereum sets 2029 quantum target as Hegotá takes shape

Stablecoin salaries can leave workers paying to access their wages

After FomoPeek Theft: You Need This New Private Key Security Guide!

Hong Kong jails ex-banker over $470K USDT bribes

Hut8 Bitcoin Mining Founder Marc van der Chijs: AI May Cause Systemic Shock, Reconfigure Back to BTC

Why is Cryptocurrency Still Rising? A Conversation on Bull Markets, Regulation, Interest Rates, and Stock Tokenization
![[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters](/public-static/18_26310349ce.png?format=avif)
[Coin Crime] "If you give us Tether, we will give you oil" - Polish state-owned company falls victim to international fraudsters

Why real-time election odds are misleading prediction market crypto traders

Ripple says asset managers prepare for XRPL Batch

500 agents and £500 million: London aims to track dirty money everywhere

RWA market reaches $34.18B as equities surge 390.4%

Delphi Digital's Latest Episode: Is Alt Season Already Here?

Crypto: Visa Cuts Rewards on Memecoin Purchases by Card

Kevin O'Leary, the 'Shark' of Canadian Business, Names the Main Threat to Bitcoin on Its Path to $1 Million

From Stablecoins to Consumer Finance, ENA is Gaining New Valuation Logic

Poverty in the World and Crypto Adoption: What If We Crossed the Two?

Caught Off Guard? Anthropic Forced to Release Model Early After Just Calling for a 'Slowdown'

Who Benefits from Interest Rate Hikes? Clarity Act's Failure Due to Established Interests

Robert Kiyosaki: The Biggest Crash in History Has Begun

What is PCE and Why September 30 is Important for Cryptocurrencies

Cryptocurrency Bill Fails, Fed Raises Rates, Yet Bitcoin Rises?

2026: The Year of Polarization in Virtual Assets

Bitcoin: JPMorgan Sees BTC Outperforming Gold

Important News from Last Night and This Morning (September 19 - September 20)

Why the Robinhood Chain Boom Has Not Led to Growth in the Ethereum Mainnet

Why Trump backed a crypto ethics rule that stopped at the family business

Circle wants you to love USDC a little like you love Chelsea








