Needle Stealer Spreads via Bogus TradingClaw On Fraudulent TradingView Clone
ID: 7e480bf5-5514-5b26-ab2b-3a7df63b3c0d
STIX ID: report--7e480bf5-5514-5b26-ab2b-3a7df63b3c0d
Feed Name: Cyber Press
Cybercriminals are operating a phishing campaign that uses a fake TradingView “AI agent” website to distribute a dropper called TradingClaw which installs Needle Stealer — a modular info-stealer that injects into browsers, harvests cookies, saved credentials, autofill data, open tabs, and crypto wallet secrets, and exfiltrates zipped data to attacker-controlled C2 servers (often using DGAs). The campaign employs social engineering, typosquatted domains, ZIP-packaged executables, persistence via extensions or scheduled tasks, and may include keylogging and screenshot capabilities; recommended mitigations include EDR behavioral detection, malware scans, safe browsing, extension and credential hygiene, and password resets from clean devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
