Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions.
The activity is linked to a wider CastleLoader campaign that gives attackers several ways to gain access to infected Windows devices.
The operation starts with fake software installers and ClickFix-style prompts that pressure victims into running harmful PowerShell commands.
Once launched, the loader can retrieve further malware without leaving obvious files behind, making early detection more difficult.
Analysts at Arctic Wolf identified the newer payloads while tracking several CastleLoader campaigns, including the Urutyka, Garrigin, and Noidret clusters.
The findings show attackers expanding from general credential theft into tools built specifically for cryptocurrency users and browser session theft.

Arctic Wolf said in a report shared with Cyber Security News (CSN) that this development raises the stakes for people who manage digital assets from their computers.
A stolen recovery phrase can give an attacker permanent control of a wallet, while a hijacked browser session may let them bypass a password reset or an existing login check.
Hackers Are Using Fake Crypto Wallet
The most notable addition is a Rust-based NeedleStealer wallet spoofer that displays a polished imitation of a desktop wallet application.
It supports brands including Ledger, Trezor, and Exodus, with the most complete fake interfaces designed to request a victim’s recovery seed phrase.

This shows how the malware presents a believable recovery prompt. Rather than exploiting a weakness in the wallet software itself, the attackers rely on a user entering the secret phrase into a screen that looks trustworthy.
In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.
The malware is unpacked in the ProgramData directory alongside a legitimate Node.js binary, helping the operation blend in with normal-looking software activity.
The shift toward wallet theft complements earlier CastleLoader activity, which has been tied to broad information stealing and remote access tools.
Readers following the CastleLoader attacks on government can see how the loader has continued to evolve into a flexible delivery platform.
The new toolkit may reflect more focused cryptocurrency targeting. Recovery phrases are especially valuable because a victim cannot simply change them after disclosure in the way they would reset a password.
The campaign also relies on familiar social engineering. Users may encounter fake update pages, misleading installers, or prompts asking them to paste a command into Windows, a tactic also seen in fake Windows update screens used to deliver information stealers.
Browser Extensions Extend Access
A second NeedleStealer component, written in Golang, installs malicious browser extensions that masquerade as legitimate software.

In the observed campaign, the extension posed as an ad blocker while quietly establishing persistent access to browser data and sessions.
This approach is dangerous because an active session token can be more useful than a password.
If attackers steal the token from a signed-in browser, they may be able to access an account without knowing the password or triggering a fresh login challenge.
The malicious extension installer also places extensions that appear legitimate, which may reduce suspicion during a quick review.
The tactic resembles other campaigns involving malicious wallet browser extensions, where deceptive add-ons seek credentials and wallet information.
Defenders should block the listed infrastructure at DNS, firewall, and endpoint layers, while treating unusual PowerShell, IronPython, Node.js, and Python activity from ProgramData or AppData as a warning sign.
Arctic Wolf also recommends application allowlisting and preventing unsigned or unexpectedly signed binaries from running in user-writable locations.
Organizations should enable PowerShell Script Block Logging and Module Logging, monitor for Mark-of-the-Web removal, and investigate Node.js execution outside approved development environments.
Staff should also be taught that a legitimate update, CAPTCHA, or verification page will not ask them to open Run and paste a command.
For security teams, reviewing browser extension permissions and watching for unauthorized changes can limit exposure to session theft.
Similar controls are relevant in fake MetaMask wallet campaigns, where attackers modified browser-based wallet environments to capture sensitive data.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev | Urutyka download server |
| File name | traffic1.ms1 | File dropped by Urutyka PowerShell stager |
| Domain | goodbytetelegramm.com | Urutyka download server |
| Domain | urutyka.com | Urutyka download server |
| Domain | drrajivparti.com | NetSupport RAT C2 |
| Domain | eazysitebuilder.com | NetSupport RAT C2 |
| IP address | 91.92.33.167 | Lobshot C2 |
| SHA-256 | 0c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9f | Related sample |
| SHA-256 | fa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638 | Related sample |
| SHA-256 | 2fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367 | Related sample |
| URL | hxxps://pub-4d5f81bf79554aa7a2187e6ffbc9702a.r2.dev/traffic1.exe | Garrigin download URL |
| URL | hxxp://94.26.90.112/dl-callback6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v | Garrigin callback URL |
| IP address | 94.26.90.112 | Garrigin callback infrastructure |
| File name | traffic1.exe | NSIS installer masquerading as Edge update |
| MD5 | 1390903f57b21f346193aefbbfd36759 | traffic1.exe hash |
| File path | ProgramData\1.exe | Dropped executable path |
| File name | ipyw32.exe | Embedded Python runtime |
| File name | antimony.txt | Encoded Python script |
| Domain | grenagana.com | CastleLoader stage-two download server |
| File name | document1 | Downloaded stage-two payload |
| IP address | 179.132.128.189 | CastleStealer C2 |
| Domain | garrigin.com | Garrigin download server |
| Domain | grorriner.com | Garrigin download server |
| Domain | ebedidance.com | NetSupport RAT C2 |
| Domain | socom-game.com | NetSupport RAT C2 |
| Domain | fangorinaf.com | Noidret NetSupport RAT download server |
| Domain | p-rala.com | NetSupport RAT C2 |
| Domain | italianhitech.com | NetSupport RAT C2 |
| Domain | strainted.com | CastleStealer download server |
| IP address | 216.107.139.188 | CastleStealer C2 |
| Domain | noidret.com | NeedleStealer Golang download server |
| IP address | 84.201.6.21 | NeedleStealer Golang C2 |
| Domain | quiantar.com | NeedleStealer Rust download server |
| Domain | kileant.com | NeedleStealer Rust and Golang C2 |
| File name | walletspoofer.exe | Rust desktop wallet-spoofer payload |
| Domain | qxvnrta.com | Digitally signed installer C2 |
| SHA-256 | edff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7 | Reference signed-installer sample |
| URL path | newpkg1 | Updated C2 URI observed for installer package |
| Domain | kaneta.cc | Staged or testing infrastructure |
| Domain | monblare.com | Domain hosted with kaneta.cc |
| SHA-256 | d26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9be | Signed installer sample |
| Domain | thenugcompany.org | Domain serving new CastleLoader stager |
| Domain | skipraid.com | Emerging infrastructure |
| Domain | claudenell.net | Finger domain |
| Domain | claudettes.net | Finger domain |
| Domain | 3teamsvoicepremium.com | Finger domain |
| Domain | avivtech.org | Domain serving Python CastleLoader payloads |
| Domain | hobtech.net | Staged domain not delivering payloads |
| Certificate subject | Mahu Agro | Code-signing certificate used by malicious installers |
| Certificate subject | TECHNOLOGY APPRAISALS LIMITED | Code-signing certificate used by malicious installers |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.