logo

Malicious trading website drops malware that hands your browser to attackers

ID: 317a0140-dfea-5f15-90da-56781f8fe1a5

STIX ID: report--317a0140-dfea-5f15-90da-56781f8fe1a5

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

...
...

## Executive summary This report analyzes an active campaign distributing Needle Stealer — a modular Golang infostealer — via a fake AI trading site (tradingclaw.pro). It documents the delivery and execution chain (ZIP download, DLL hijacking, loader iviewers.dll, process hollowing into RegAsm.exe), the stealer's features (browser data theft, wallet spoofers, malicious browser extensions with broad permissions), C2 endpoints and IOCs (hashes, domains, IPs), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.