Skip to content
Malware

Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions. The activity is linked to a wider CastleLoader campaign that gives attackers several ways to gain access to infected Windows devices. The operation...

· Jul 28, 2026 · 6 min read · 👁 1 views
Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions.

The activity is linked to a wider CastleLoader campaign that gives attackers several ways to gain access to infected Windows devices.

The operation starts with fake software installers and ClickFix-style prompts that pressure victims into running harmful PowerShell commands.

Once launched, the loader can retrieve further malware without leaving obvious files behind, making early detection more difficult.

Analysts at Arctic Wolf identified the newer payloads while tracking several CastleLoader campaigns, including the Urutyka, Garrigin, and Noidret clusters.

The findings show attackers expanding from general credential theft into tools built specifically for cryptocurrency users and browser session theft.

Stage 2 python injector (Source - Arctic Wolf)
Stage 2 python injector (Source – Arctic Wolf)

Arctic Wolf said in a report shared with Cyber Security News (CSN) that this development raises the stakes for people who manage digital assets from their computers.

A stolen recovery phrase can give an attacker permanent control of a wallet, while a hijacked browser session may let them bypass a password reset or an existing login check.

Hackers Are Using Fake Crypto Wallet

The most notable addition is a Rust-based NeedleStealer wallet spoofer that displays a polished imitation of a desktop wallet application.

It supports brands including Ledger, Trezor, and Exodus, with the most complete fake interfaces designed to request a victim’s recovery seed phrase.

Wallet Spoofer’s fake user interfaces (Click to enlarge) (Source – Arctic Wolf)

This shows how the malware presents a believable recovery prompt. Rather than exploiting a weakness in the wallet software itself, the attackers rely on a user entering the secret phrase into a screen that looks trustworthy.

In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.

The malware is unpacked in the ProgramData directory alongside a legitimate Node.js binary, helping the operation blend in with normal-looking software activity.

The shift toward wallet theft complements earlier CastleLoader activity, which has been tied to broad information stealing and remote access tools.

Readers following the CastleLoader attacks on government can see how the loader has continued to evolve into a flexible delivery platform.

The new toolkit may reflect more focused cryptocurrency targeting. Recovery phrases are especially valuable because a victim cannot simply change them after disclosure in the way they would reset a password.

The campaign also relies on familiar social engineering. Users may encounter fake update pages, misleading installers, or prompts asking them to paste a command into Windows, a tactic also seen in fake Windows update screens used to deliver information stealers.

Browser Extensions Extend Access

A second NeedleStealer component, written in Golang, installs malicious browser extensions that masquerade as legitimate software.

Icons inside fake extension (Source - Arctic Wolf)
Icons inside fake extension (Source – Arctic Wolf)

In the observed campaign, the extension posed as an ad blocker while quietly establishing persistent access to browser data and sessions.

This approach is dangerous because an active session token can be more useful than a password.

If attackers steal the token from a signed-in browser, they may be able to access an account without knowing the password or triggering a fresh login challenge.

The malicious extension installer also places extensions that appear legitimate, which may reduce suspicion during a quick review.

The tactic resembles other campaigns involving malicious wallet browser extensions, where deceptive add-ons seek credentials and wallet information.

Defenders should block the listed infrastructure at DNS, firewall, and endpoint layers, while treating unusual PowerShell, IronPython, Node.js, and Python activity from ProgramData or AppData as a warning sign.

Arctic Wolf also recommends application allowlisting and preventing unsigned or unexpectedly signed binaries from running in user-writable locations.

Organizations should enable PowerShell Script Block Logging and Module Logging, monitor for Mark-of-the-Web removal, and investigate Node.js execution outside approved development environments.

Staff should also be taught that a legitimate update, CAPTCHA, or verification page will not ask them to open Run and paste a command.

For security teams, reviewing browser extension permissions and watching for unauthorized changes can limit exposure to session theft.

Similar controls are relevant in fake MetaMask wallet campaigns, where attackers modified browser-based wallet environments to capture sensitive data.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domainpub-6728b11f74fd435f926ed25c5f2952bb.r2.devUrutyka download server
File nametraffic1.ms1File dropped by Urutyka PowerShell stager
Domaingoodbytetelegramm.comUrutyka download server
Domainurutyka.comUrutyka download server
Domaindrrajivparti.comNetSupport RAT C2
Domaineazysitebuilder.comNetSupport RAT C2
IP address91.92.33.167Lobshot C2
SHA-2560c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9fRelated sample
SHA-256fa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638Related sample
SHA-2562fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367Related sample
URLhxxps://pub-4d5f81bf79554aa7a2187e6ffbc9702a.r2.dev/traffic1.exeGarrigin download URL
URLhxxp://94.26.90.112/dl-callback6dkcdpd7-4jacbuf9-prutgux4-2ybssc8vGarrigin callback URL
IP address94.26.90.112Garrigin callback infrastructure
File nametraffic1.exeNSIS installer masquerading as Edge update
MD51390903f57b21f346193aefbbfd36759traffic1.exe hash
File pathProgramData\1.exeDropped executable path
File nameipyw32.exeEmbedded Python runtime
File nameantimony.txtEncoded Python script
Domaingrenagana.comCastleLoader stage-two download server
File namedocument1Downloaded stage-two payload
IP address179.132.128.189CastleStealer C2
Domaingarrigin.comGarrigin download server
Domaingrorriner.comGarrigin download server
Domainebedidance.comNetSupport RAT C2
Domainsocom-game.comNetSupport RAT C2
Domainfangorinaf.comNoidret NetSupport RAT download server
Domainp-rala.comNetSupport RAT C2
Domainitalianhitech.comNetSupport RAT C2
Domainstrainted.comCastleStealer download server
IP address216.107.139.188CastleStealer C2
Domainnoidret.comNeedleStealer Golang download server
IP address84.201.6.21NeedleStealer Golang C2
Domainquiantar.comNeedleStealer Rust download server
Domainkileant.comNeedleStealer Rust and Golang C2
File namewalletspoofer.exeRust desktop wallet-spoofer payload
Domainqxvnrta.comDigitally signed installer C2
SHA-256edff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7Reference signed-installer sample
URL pathnewpkg1Updated C2 URI observed for installer package
Domainkaneta.ccStaged or testing infrastructure
Domainmonblare.comDomain hosted with kaneta.cc
SHA-256d26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9beSigned installer sample
Domainthenugcompany.orgDomain serving new CastleLoader stager
Domainskipraid.comEmerging infrastructure
Domainclaudenell.netFinger domain
Domainclaudettes.netFinger domain
Domain3teamsvoicepremium.comFinger domain
Domainavivtech.orgDomain serving Python CastleLoader payloads
Domainhobtech.netStaged domain not delivering payloads
Certificate subjectMahu AgroCode-signing certificate used by malicious installers
Certificate subjectTECHNOLOGY APPRAISALS LIMITEDCode-signing certificate used by malicious installers

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you