Fake TradingView AI Agent Site is Delivering Needle Stealer Malware via Fake TradingClaw
ID: e7d211a9-b07e-5ec8-ba2d-eb5bace9c801
STIX ID: report--e7d211a9-b07e-5ec8-ba2d-eb5bace9c801
Feed Name: cybersecurityNews.com
A malicious campaign hosted at tradingclaw.pro impersonates an AI trading product to trick victims into downloading a ZIP that uses DLL hijacking (abusing RegAsm.exe) and process hollowing to deploy Needle Stealer — a modular Golang infostealer that harvests browser cookies, saved credentials, crypto wallet data, installs malicious browser extensions, and spoofs wallets to steal funds; the site selectively serves malicious content to avoid scanners and reuses a known loader to deliver the new payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
