Other strategies that HP reported include phishing campaigns that hid a QR code inside a PDF invoice. In this case, attackers coaxed potential victims to use their phones and scan QR codes on the invoice. That strategy moves them away from the protections guarding a work PC. So, even after blocking a threat on a computer, hackers could still access their targets through mobile devices.
Nothing to Do With Actual Wallet Breaches
Hackers capitalize on the common pattern of integrating crypto wallets into browsers as extensions by implementing these techniques. The malware compares the 32-character IDs of the extensions it finds with a predefined list, searching for the IDs of seven crypto wallets, including Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper.
The security threat that HP highlighted does not involve wallet breaches. Instead, it focuses on luring users and deceiving them through search results and ads. They appeal to their eagerness to find efficient trading solutions, particularly AI tools that can help them make money and potentially improve their trading experience.
Key Indicators to Watch
The HP Wolf Security Report highlighted key indicators users should watch out for to keep safe from the identified threat. The malware operates by forcefully killing a target’s web browser process so it can unpack and overwrite the extension folder. Therefore, an abrupt browser shutdown and restart is a red flag.
HP noted that the malware typically terminates and restarts the victims’ internet session and requests them to enter their wallet ID and password on a “familiar” screen. That is a key indicator of a credential trap that crypto users need to be wary of. Attackers often distribute the fake AI trading software via sponsored search results or ads as compressed files.
Crypto users should be highly suspicious of trading tools that require manual zip installation rather than an official deployment from an app store or web store. As a rule of thumb, HP recommends completely avoiding opaque, unverified agent applications and keeping sensitive financial workflows isolated from third-party tools.
The Original Phantom Stealer
The highlighted threat impersonates “Phantom Stealer,” a sophisticated Windows-focused information-stealing malware offered commercially under a Malware-as-a-Service (MaaS) subscription model. Phantom Stealer is designed to covertly harvest sensitive data directly from infected machines, targeting web browsers to siphon saved credentials, session cookies, autofill data, and payment information.
The ethical malware seller offers two components: a stealer, which is the final payload that exfiltrates sensitive data from infected devices, and a crypter that encrypts and protects the payload from analysis and reverse engineering. However, HP noted that virtually no attacker will adhere to the marketer’s ethical condition, which is agreeing not to use the toolkit for malicious purposes.
Related: Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware