Cybercriminals Create Fake AI Agents to Install Malware and Steal Cryptocurrencies
Cybercriminals use fake artificial intelligence (AI) agents to trick users into installing malware that replaces legitimate cryptocurrency wallet extensions and steals their passwords. The maneuver was detected between April and June by HP, in a scenario where agentic artificial intelligence, systems capable of performing tasks on behalf of the user, has become a new lure for financial fraud. This activity is part of HP's Threat Insights Report, which analyzed millions of devices protected by HP Wolf Security to identify recent campaigns and the methods used to evade detection systems.
How This Cyberattack That Steals Cryptocurrencies Operates
The attack presents itself as an alternative to traditional financial advisors: cybercriminals promise a tool that monitors cryptocurrency portfolios and operates automatically. The site tradingclaw posed as an AI assistant for trading digital assets, but distributed a family of malware called Needle Stealer. Once installed, the program scans browsers for wallet extensions, including Coinbase and MetaMask. When the program finds them, it replaces them with visually similar copies; by entering their login details, victims hand over their credentials to the attackers, who can access their funds. Patrick Schläpfer, a principal researcher at HP Security Lab, warned that attackers "are leveraging the adoption of agentic AI tools to develop new lures that deceive users into downloading malicious software that appears legitimate." In his view, this strategy makes the distribution of these programs "more sophisticated and harder to detect."
What Other Cyberattacks Were Identified
The second detected campaign combines Phantom Gate, a malware loader, with Phantom Stealer, a tool aimed at stealing information, including credentials and financial data. Phantom Stealer is marketed as a legitimate program for penetration testing, while Phantom Gate allows criminals to deploy and expand infection campaigns. Schläpfer stated that these tools reflect "the expansion of the threat landscape" because they enable the construction of "dangerous infection chains." The result is an increased risk of organizations being compromised. The third modality resorts to phishing, a scam that impersonates pages or services to obtain personal data, through QR codes. Victims receive PDF files with blurred content under the pretext that it was hidden "for security reasons," and they are asked to scan the code with their phone to access the information. The code redirects the user to a fraudulent page from the device. Those addresses would have been blocked when opened from a computer, but they work on phones, which have lower protection levels and expose access credentials.
How It Was Possible to Detect Different Cyberattacks
HP Wolf Security can observe these attacks because it runs suspicious programs within protected containers. This isolation allows for understanding the behavior of criminals without affecting the device. Users protected by this service opened 60 billion email attachments, web pages, and downloaded files without any security breaches being recorded. The data showed that at least 10% of the threats detected by email through HP Sure Click managed to evade one or more scanners from the email gateways. Additionally, executable files were the most frequent distribution mechanism, appearing in 40% of cases. Compressed files accounted for 38%, while PDFs reached 7.5%. James Wright, global director of Personal Systems Security at HP, noted that users "constantly move between devices and applications" through browsers and AI tools, and that criminals quickly update their tactics to follow them. Therefore, he urged organizations to adopt a zero-trust model based on isolation and containment of untrusted clicks and downloads.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Two routes now open after heavy blow to crucial crypto bill

Open-source Memecoin launchpad adds 1,373 lines of solidity in latest development release

France crypto home attack steals €40,000: Report

Bitcoin: VanEck Criticizes Metaplanet's Compensation Model

Stablecoin salaries can leave workers paying to access their wages

Hong Kong jails ex-banker over $470K USDT bribes

Retail Short Selling Ratio in US Stocks Rises to 53%, Institutions Say Near Rebound Zone

Crypto: Visa Cuts Rewards on Memecoin Purchases by Card

Bitcoin one-year HODL wave rises to 63.3%, but signals limited demand

Robert Kiyosaki: The Biggest Crash in History Has Begun

2026: The Year of Polarization in Virtual Assets

Paraguay Seizes 35 Illegal Cryptocurrency Mining Machines

GSR Study Shows Over 2,300 Token Listings Have Median Prices Falling Below Issue Price Within 3 Days, 50% Drop Within 90 Days

106 National Embodied Intelligence Data Collection Centers Established, Over 5,000 Robots

Banning stablecoin yields barely boosts bank credit

Market Focus Next Week on Trump's Middle East Decisions and Federal Reserve Rate Hike Impact

Grayscale: Bitcoin Could Withstand New Rate Hikes from the FED

Bitbox Integrates Lightning with Spark in Hardware Wallet

Hyperliquid's Path to the U.S. Revealed: Kraken's Parent Company Accesses via HIP-3, Restrictions Remain Stringent

Criminals can hide stolen cryptocurrencies, but they are not untraceable

The Three Words and One Answer from Yesterday's Press Conference: Wall Street is Pondering 'Waller's Approach'

El Niño Dries Up Dams, Ethiopia Rationing Bitcoin Miners

Crypto vs Cash: 3 Clandestine Trading Posts Raided in London
![[Exclusive] Controversy Over Private VIP Event for Virtual Assets... Upbit and Bithumb Claim 'Never Held'](/public-static/21_2c30f7df62.png?format=avif)
[Exclusive] Controversy Over Private VIP Event for Virtual Assets... Upbit and Bithumb Claim 'Never Held'

Bitcoin Spot ETF Sees Net Inflow of $433 Million Yesterday, Fidelity's FBTC Leads with $311 Million

Anthropic Partners with Accenture to Launch Embedded Evaluation Program

This Week's Macroeconomic Highlights: Waller's First Rate Hike, Saudi Arabia Repairs Oil Pipeline Lifeline

Visa Closes Cashback Loophole for Meme Coin Credit Card Purchases

OpenAI CEO Altman to Address AI Safety Issues at UN Security Council Next Week








