logo

Needle Stealer Spreads via Bogus TradingClaw On Fraudulent TradingView Clone

ID: 7e480bf5-5514-5b26-ab2b-3a7df63b3c0d

STIX ID: report--7e480bf5-5514-5b26-ab2b-3a7df63b3c0d

Feed Name: Cyber Press

Threat Score
74/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Varshini

...
...

Cybercriminals are operating a phishing campaign that uses a fake TradingView “AI agent” website to distribute a dropper called TradingClaw which installs Needle Stealer — a modular info-stealer that injects into browsers, harvests cookies, saved credentials, autofill data, open tabs, and crypto wallet secrets, and exfiltrates zipped data to attacker-controlled C2 servers (often using DGAs). The campaign employs social engineering, typosquatted domains, ZIP-packaged executables, persistence via extensions or scheduled tasks, and may include keylogging and screenshot capabilities; recommended mitigations include EDR behavioral detection, malware scans, safe browsing, extension and credential hygiene, and password resets from clean devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.