logo

New Torg Grabber infostealer malware targets 728 crypto wallets

ID: a5226b04-2216-550c-af89-f03d3349cae8

STIX ID: report--a5226b04-2216-550c-af89-f03d3349cae8

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-03-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Torg Grabber is an actively developed info-stealer that uses a clipboard hijack (ClickFix) to get victims to run a malicious PowerShell command, then runs in-memory via reflective loading and direct syscalls to steal credentials, cookies, autofill data and files across 25 Chromium-based browsers and 8 Firefox variants and targets 850 browser extensions (728 of which are cryptocurrency wallets) plus numerous password managers and authenticators; it employs anti-analysis, ABE bypasses, ChaCha-encrypted payload delivery via Cloudflare-routed HTTPS, frequent C2 churn, and the ability to execute shellcode and extract browser master keys, posing a high risk to users holding crypto assets and sensitive credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.