Cybercriminals are exploiting growing interest in agentic AI by promoting fake AI Trading Tools designed to infect users with malware, according to research from HP Wolf Security covering activity between April and June 2026.
The campaign targets users with fraudulent AI trading agents that appear to offer automated cryptocurrency trading capabilities. Once the malicious software is installed, it scans the victim’s browser for cryptocurrency wallet extensions, including Coinbase and MetaMask.
MetaMask has also added real-time questions to catch romance and investment scams.
The malware can then replace legitimate wallet extensions with malicious copies. When victims enter their login information into the spoofed extensions, those credentials are captured and transmitted to the attackers, potentially giving them access to cryptocurrency holdings.
“Lots of users have already played with AI chatbots and now are interested in trying different AI agents that are available but it is difficult to distinguish an AI agent that is benign or malware,” said Patrick Schläpfer, Principal Threat Researcher at HP, during a media briefing for the HP Wolf Security Threat Insights Report.
The campaign illustrates how criminals can use legitimate interest in emerging technology as a delivery mechanism for malware. Rather than relying solely on conventional phishing messages, attackers are presenting malicious software as useful AI-powered products.
Schläpfer said the malware also uses DLL side-loading to help bypass security checks before executing its payload.
“Threat actors make use of a technique called DLL side-loading. First the windows defender smart screen checks the executable for threats. So, naturally, the detection lets the executable run without interruption,” Schläpfer said.
Once executed, the malware uses a technique identified by HP as Needle Steeler to search browsers for cryptocurrency wallet extensions. The discovery of a wallet installation provides the malware with a specific target for credential theft.
AI Trading Tools are used to disguise wallet-stealing malware
The use of fake AI Trading Tools is particularly significant because users may approach automated trading products expecting them to interact with cryptocurrency wallets or exchanges.
In the campaign described by HP, however, the apparent trading functionality serves as a lure. The malware’s actual purpose is to identify cryptocurrency wallets and replace legitimate browser extensions with malicious lookalikes.
The affected extensions can imitate familiar interfaces closely enough to encourage users to enter sensitive information. Once credentials are submitted, the information is sent to the threat actor.
The approach creates a security risk beyond simply downloading a malicious application. Users may believe they are installing a new trading assistant while unknowingly granting malware an opportunity to inspect their browser environment and target digital-asset credentials.
HP’s research also points to a broader problem: malicious actors can package malware inside software that appears to have legitimate business or technical purposes.
That trend is also visible in the Phantom Gate campaign identified by researchers. Phantom Gate is described as a malware loader that appears to extend the Phantom Stealer campaign. Phantom Stealer itself has been openly marketed as penetration-testing software, while the Phantom Gate mechanism can be used to deliver the final malicious payload.
“Phantom Gate encrypts the malware to make it more difficult to recognise,” Schläpfer said.
“The idea of PhantomGate is to download and decode the final payload. The ecosystem is growing, giving less experienced technical criminals materials to act.”
The development means attackers with less technical expertise can potentially use existing malware components and delivery mechanisms to assemble campaigns rather than developing every component themselves.
QR-code phishing moves victims to less-protected phones
HP also identified another technique that complements the broader campaign: quishing, or phishing attacks that use QR codes.
Instead of directing victims immediately to a malicious website on their computers, attackers send PDF documents containing apparently protected or blurred content. The documents instruct recipients to scan a QR code with a mobile phone.
The QR code then redirects the victim to a phishing page that may be inaccessible from the computer because of corporate security controls.
Schläpfer described the tactic as a deliberate attempt to move users away from devices with stronger security protections.
“Users are forced from a well protected device like a business laptop to go to a less-secure device like a mobile phone,” Schläpfer said. “The phishing URL stored within the QR code might be blocked in the laptop but naturally on a mobile phone, you don’t have the same protection systems and therefore the link may not be blocked.”
The phishing process can then display a fake security verification message while the system supposedly checks whether the destination URL is safe.
“This is a fake message to trick the user,” Schläpfer said. “They [the malware systems] are trying to blend into a normal business process to make the user feel comfortable to lead them into a turnstile capture.”
The turnstile mechanism acts as an initial verification step before redirecting victims to a OneDrive-branded page containing email information. The information can then be captured by the attackers.
HP said 10% of email threats identified by its Sure Click technology successfully bypassed one or more traditional email gateway scanners, highlighting the limitations of relying solely on conventional email filtering.
AI Trading Tools add to a wider digital security challenge
The findings place fake AI Trading Tools within a wider ecosystem of attacks that combine social engineering, malware loaders and credential theft.
The threat is not limited to individual crypto traders. The use of familiar enterprise services such as Microsoft OneDrive in phishing flows demonstrates how attackers can exploit trusted brands and normal workplace processes to make malicious activity appear legitimate.
“Sure Click doesn’t trust anything,” said Pelle Aardewerk, CISO Cyber Security Advisory Lead at HP. “It’s always opening in a micro-virtual machine, so even if what they click on is bad, it cannot escape or impact the host or network. It’s a preventative mechanism that still gives people the productivity they need to do their normal work.”
Sure Access is designed to isolate sensitive tasks in a separate hardened session, while Sure Recover provides mechanisms for restoring compromised devices.
“Digital resilience is a key topic at conferences… it will never 100% exist in security,” Aardewerk said. “Hackers are creative so if things go wrong, the question is how quickly can we recover and go back to productive business-critical operations.”