Exodus and Trezor: Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

Exodus and Trezor: Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft

Cybercriminals behind the CastleLoader malware campaign are escalating attacks by deploying sophisticated tools to steal cryptocurrency recovery phrases, login credentials, and active browser sessions. Researchers at Arctic Wolf identified the latest evolution of the campaign, which now targets digital asset holders with fake wallet interfaces and malicious browser extensions.

How the Attack Works

The operation begins with fake software installers and ClickFix-style prompts, tricking victims into executing harmful PowerShell commands. Once executed, the CastleLoader malware retrieves additional payloads including Python injectors and Rust-based stealers without leaving obvious traces, complicating early detection.

Key components of the campaign include:

  • NeedleStealer (Rust-based wallet spoofer): Mimics popular wallet brands (Ledger, Trezor, Exodus) with polished fake interfaces designed to trick users into entering their recovery seed phrases. Unlike traditional exploits, this attack relies on social engineering rather than software vulnerabilities.
  • Golang-based malicious browser extensions: Disguised as legitimate tools (e.g., ad blockers), these extensions hijack active browser sessions, allowing attackers to bypass passwords and access accounts without triggering new login challenges.
  • Node.js-based injectors: Used in the Noidret campaign, these tools unpack malware in the ProgramData directory alongside legitimate binaries, blending in with normal system activity.

Why This Matters

  • Irreversible wallet theft: Unlike passwords, recovery phrases cannot be reset once stolen, attackers gain permanent control of a victim’s cryptocurrency holdings.
  • Session hijacking risks: Stolen browser tokens enable attackers to access accounts without passwords, evading security measures like two-factor authentication.
  • Evolving tactics: The campaign reflects a shift from general credential theft to specialized crypto-targeting, leveraging social engineering (fake updates, misleading installers) to deceive users.

Campaign Clusters & Infrastructure

Arctic Wolf tracked multiple CastleLoader clusters, including:

  • Urutyka (PowerShell stagers, NetSupport RAT)
  • Garrigin (NSIS installers masquerading as Edge updates)
  • Noidret (Node.js-based wallet spoofers)

Indicators of compromise (IoCs) include domains like pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev (Urutyka download server) and IPs such as 91.92.33.167 (Lobshot C2). Malicious files, including walletspoofer.exe and traffic1.exe, were observed in ProgramData and AppData directories.

Defensive Recommendations (For Security Teams)

  • Block listed infrastructure at DNS, firewall, and endpoint layers.
  • Monitor unusual activity from PowerShell, Node.js, and Python in user-writable locations.
  • Enable PowerShell logging and investigate Mark-of-the-Web (MOTW) removal.
  • Restrict unsigned binaries in sensitive directories.
  • Review browser extension permissions for unauthorized changes.

The campaign underscores the growing threat of crypto-focused malware, where attackers exploit human trust rather than technical flaws to compromise digital assets.

Source: https://cybersecuritynews.com/hackers-are-using-fake-crypto-wallet-screens/

Exodus TPRM report: https://www.rankiteo.com/company/exodus-io

Trezor TPRM report: https://www.rankiteo.com/company/trezor

"id": "exotre1785241575",
"linkid": "exodus-io, trezor",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Cryptocurrency', 'FinTech'],
                        'type': 'Individuals and organizations holding '
                                'cryptocurrency'}],
 'attack_vector': ['Fake software installers',
                   'ClickFix-style prompts',
                   'Malicious PowerShell commands',
                   'Social engineering'],
 'data_breach': {'sensitivity_of_data': 'High (irreversible loss of '
                                        'cryptocurrency access)',
                 'type_of_data_compromised': ['Cryptocurrency recovery phrases',
                                              'Login credentials',
                                              'Browser session tokens']},
 'description': 'Cybercriminals behind the CastleLoader malware campaign are '
                'escalating attacks by deploying sophisticated tools to steal '
                'cryptocurrency recovery phrases, login credentials, and '
                'active browser sessions. Researchers at Arctic Wolf '
                'identified the latest evolution of the campaign, which now '
                'targets digital asset holders with fake wallet interfaces and '
                'malicious browser extensions.',
 'impact': {'data_compromised': ['Cryptocurrency recovery phrases',
                                 'Login credentials',
                                 'Browser session tokens'],
            'financial_loss': 'Irreversible wallet theft leading to permanent '
                              'loss of cryptocurrency holdings',
            'identity_theft_risk': 'High (due to stolen recovery phrases and '
                                   'session tokens)',
            'payment_information_risk': 'High (cryptocurrency wallets)',
            'systems_affected': ['User systems with installed malware',
                                 'Browser extensions']},
 'initial_access_broker': {'entry_point': ['Fake software installers',
                                           'ClickFix-style prompts'],
                           'high_value_targets': 'Cryptocurrency wallet '
                                                 'holders'},
 'lessons_learned': 'The campaign underscores the growing threat of '
                    'crypto-focused malware, where attackers exploit human '
                    'trust rather than technical flaws to compromise digital '
                    'assets.',
 'motivation': ['Financial gain', 'Cryptocurrency theft'],
 'post_incident_analysis': {'corrective_actions': ['Block malicious domains '
                                                   'and IPs',
                                                   'Monitor PowerShell, '
                                                   'Node.js, and Python '
                                                   'activity',
                                                   'Restrict unsigned binaries',
                                                   'Review browser extension '
                                                   'permissions'],
                            'root_causes': ['Social engineering (fake wallet '
                                            'interfaces, misleading '
                                            'installers)',
                                            'Malicious PowerShell commands',
                                            'Rust-based and Node.js-based '
                                            'malware']},
 'recommendations': ['Block listed infrastructure at DNS, firewall, and '
                     'endpoint layers.',
                     'Monitor unusual activity from PowerShell, Node.js, and '
                     'Python in user-writable locations.',
                     'Enable PowerShell logging and investigate '
                     'Mark-of-the-Web (MOTW) removal.',
                     'Restrict unsigned binaries in sensitive directories.',
                     'Review browser extension permissions for unauthorized '
                     'changes.'],
 'references': [{'source': 'Arctic Wolf'}],
 'response': {'containment_measures': ['Block listed infrastructure at DNS, '
                                       'firewall, and endpoint layers',
                                       'Monitor unusual activity from '
                                       'PowerShell, Node.js, and Python'],
              'enhanced_monitoring': 'Review browser extension permissions for '
                                     'unauthorized changes',
              'remediation_measures': ['Enable PowerShell logging',
                                       'Investigate Mark-of-the-Web (MOTW) '
                                       'removal',
                                       'Restrict unsigned binaries in '
                                       'sensitive directories'],
              'third_party_assistance': 'Arctic Wolf (research and analysis)'},
 'threat_actor': 'CastleLoader Campaign Operators',
 'title': 'CastleLoader Campaign Expands with Crypto Wallet Spoofing and '
          'Browser Session Theft',
 'type': ['Malware Campaign', 'Cryptocurrency Theft', 'Session Hijacking']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.