Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Criminals are using convincing cryptocurrency wallet screens and browser extensions to steal recovery phrases, login data, and active browser sessions.

The activity is linked to a wider CastleLoader campaign that gives attackers several ways to gain access to infected Windows devices.

The operation starts with fake software installers and ClickFix-style prompts that pressure victims into running harmful PowerShell commands.

Once launched, the loader can retrieve further malware without leaving obvious files behind, making early detection more difficult.

Analysts at Arctic Wolf identified the newer payloads while tracking several CastleLoader campaigns, including the Urutyka, Garrigin, and Noidret clusters.

The findings show attackers expanding from general credential theft into tools built specifically for cryptocurrency users and browser session theft.

Stage 2 python injector (Source – Arctic Wolf)

Arctic Wolf said in a report shared with Cyber Security News (CSN) that this development raises the stakes for people who manage digital assets from their computers.

A stolen recovery phrase can give an attacker permanent control of a wallet, while a hijacked browser session may let them bypass a password reset or an existing login check.

Hackers Are Using Fake Crypto Wallet

The most notable addition is a Rust-based NeedleStealer wallet spoofer that displays a polished imitation of a desktop wallet application.

It supports brands including Ledger, Trezor, and Exodus, with the most complete fake interfaces designed to request a victim’s recovery seed phrase.

Wallet Spoofer’s fake user interfaces (Click to enlarge) (Source – Arctic Wolf)

This shows how the malware presents a believable recovery prompt. Rather than exploiting a weakness in the wallet software itself, the attackers rely on a user entering the secret phrase into a screen that looks trustworthy.

In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.

The malware is unpacked in the ProgramData directory alongside a legitimate Node.js binary, helping the operation blend in with normal-looking software activity.

The shift toward wallet theft complements earlier CastleLoader activity, which has been tied to broad information stealing and remote access tools.

Readers following the CastleLoader attacks on government can see how the loader has continued to evolve into a flexible delivery platform.

The new toolkit may reflect more focused cryptocurrency targeting. Recovery phrases are especially valuable because a victim cannot simply change them after disclosure in the way they would reset a password.

The campaign also relies on familiar social engineering. Users may encounter fake update pages, misleading installers, or prompts asking them to paste a command into Windows, a tactic also seen in fake Windows update screens used to deliver information stealers.

Browser Extensions Extend Access

A second NeedleStealer component, written in Golang, installs malicious browser extensions that masquerade as legitimate software.

Icons inside fake extension (Source – Arctic Wolf)

In the observed campaign, the extension posed as an ad blocker while quietly establishing persistent access to browser data and sessions.

This approach is dangerous because an active session token can be more useful than a password.

If attackers steal the token from a signed-in browser, they may be able to access an account without knowing the password or triggering a fresh login challenge.

The malicious extension installer also places extensions that appear legitimate, which may reduce suspicion during a quick review.

The tactic resembles other campaigns involving malicious wallet browser extensions, where deceptive add-ons seek credentials and wallet information.

Defenders should block the listed infrastructure at DNS, firewall, and endpoint layers, while treating unusual PowerShell, IronPython, Node.js, and Python activity from ProgramData or AppData as a warning sign.

Arctic Wolf also recommends application allowlisting and preventing unsigned or unexpectedly signed binaries from running in user-writable locations.

Organizations should enable PowerShell Script Block Logging and Module Logging, monitor for Mark-of-the-Web removal, and investigate Node.js execution outside approved development environments.

Staff should also be taught that a legitimate update, CAPTCHA, or verification page will not ask them to open Run and paste a command.

For security teams, reviewing browser extension permissions and watching for unauthorized changes can limit exposure to session theft.

Similar controls are relevant in fake MetaMask wallet campaigns, where attackers modified browser-based wallet environments to capture sensitive data.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev Urutyka download server
File name traffic1.ms1 File dropped by Urutyka PowerShell stager
Domain goodbytetelegramm.com Urutyka download server
Domain urutyka.com Urutyka download server
Domain drrajivparti.com NetSupport RAT C2
Domain eazysitebuilder.com NetSupport RAT C2
IP address 91.92.33.167 Lobshot C2
SHA-256 0c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9f Related sample
SHA-256 fa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638 Related sample
SHA-256 2fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367 Related sample
URL hxxps://pub-4d5f81bf79554aa7a2187e6ffbc9702a.r2.dev/traffic1.exe Garrigin download URL
URL hxxp://94.26.90.112/dl-callback6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v Garrigin callback URL
IP address 94.26.90.112 Garrigin callback infrastructure
File name traffic1.exe NSIS installer masquerading as Edge update
MD5 1390903f57b21f346193aefbbfd36759 traffic1.exe hash
File path ProgramData1.exe Dropped executable path
File name ipyw32.exe Embedded Python runtime
File name antimony.txt Encoded Python script
Domain grenagana.com CastleLoader stage-two download server
File name document1 Downloaded stage-two payload
IP address 179.132.128.189 CastleStealer C2
Domain garrigin.com Garrigin download server
Domain grorriner.com Garrigin download server
Domain ebedidance.com NetSupport RAT C2
Domain socom-game.com NetSupport RAT C2
Domain fangorinaf.com Noidret NetSupport RAT download server
Domain p-rala.com NetSupport RAT C2
Domain italianhitech.com NetSupport RAT C2
Domain strainted.com CastleStealer download server
IP address 216.107.139.188 CastleStealer C2
Domain noidret.com NeedleStealer Golang download server
IP address 84.201.6.21 NeedleStealer Golang C2
Domain quiantar.com NeedleStealer Rust download server
Domain kileant.com NeedleStealer Rust and Golang C2
File name walletspoofer.exe Rust desktop wallet-spoofer payload
Domain qxvnrta.com Digitally signed installer C2
SHA-256 edff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7 Reference signed-installer sample
URL path newpkg1 Updated C2 URI observed for installer package
Domain kaneta.cc Staged or testing infrastructure
Domain monblare.com Domain hosted with kaneta.cc
SHA-256 d26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9be Signed installer sample
Domain thenugcompany.org Domain serving new CastleLoader stager
Domain skipraid.com Emerging infrastructure
Domain claudenell.net Finger domain
Domain claudettes.net Finger domain
Domain 3teamsvoicepremium.com Finger domain
Domain avivtech.org Domain serving Python CastleLoader payloads
Domain hobtech.net Staged domain not delivering payloads
Certificate subject Mahu Agro Code-signing certificate used by malicious installers
Certificate subject TECHNOLOGY APPRAISALS LIMITED Code-signing certificate used by malicious installers

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.