GDN DESKTOP 1

Advertisement

Cybercriminals deploy fake AI trading agents, QR codes to steal crypto wallets – HP warns

Artificial Intelligence (AI). PHOTO; FORBES

HP’s latest Threat Insights Report has revealed that cybercriminals are advertising fake Artificial Intelligence (AI) trading agents to trick cryptocurrency users and other victims into downloading malicious software.

The report, released on September 22, 2026, noted that once the software is downloaded, victims’ browsers are scanned for crypto wallet extensions like Coinbase and MetaMask, replacing them with malicious lookalikes that harvest any credentials entered.

The report stated that once harvested, the cyberattackers have easy access to steal crypto holdings.

The report, which examined data from April-June 2026, detailed how cybercriminals continue to diversify attack methods to bypass security tools, revealing that at least 10 per cent of email threats identified by HP Sure Click bypassed one or more email gateway scanner.

Advertisement

The report stated that executable files were the most popular malware delivery type, accounting for 40 per cent, followed by archive files at 38 per cent and PDF documents at 7.5 per cent.

The report explained that attackers use QR codes to shift credential theft onto less-protected mobile devices, and continue to invest in specialised malware capability modules like the Phantom Gate loader to expand existing malware campaigns.

EFN Non Oil Export

Researchers noted that combining Phantom Stealer malware, which is openly marketed as legitimate penetration-testing software, with Phantom Gate, a new malware loader mechanism, makes it easier for threat actors to build and scale attack campaigns.

The report also identified QR phishing as a common credential theft route, which moves users from PCs to mobile devices that may have weaker protections.

Advertisement

HP researchers observed malicious PDFs claiming content was “blurred for security,’ prompting users to scan QR codes for authenticated access and redirecting them to phishing sites to steal login credentials.

The report further identified continued threat actor investment in developing tools to scale phishing and malware deployment.

” This tells us that organisations should assume malicious links, files and downloads may evade traditional detection. It highlights the importance of integrating isolation and containment into a zero-trust approach to prevent untrusted clicks and downloads from becoming endpoint compromises,'” HP stated.

Principal Threat Researcher, HP Security Lab, Patrick Schläpfer, stressed that attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate.
He said this tactic makes malware delivery more polished and harder to detect.

“New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organisations,” he said.

HP’s Global Head of Security for Personal Systems, James Wright, said users constantly move between devices and applications, such as browsers and new AI tools, while attackers are quick to follow.

Wright said security needs to work across all of those interactions without getting in people’s way.

“That means organisations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk,” he noted.

Join Our Channels

Taboola Recommendation Widget