Cybercriminals are using fake AI-powered crypto agents to deliver malware that can replace browser wallet extensions with malicious lookalikes, according to HP’s September 2026 Threat Insights Report. The campaign promoted a purported automated crypto-trading assistant, but the downloaded file installed Needle Stealer instead.
Needle Stealer checked installed browser extensions and attempted to substitute targeted digital-wallet apps with versions designed to mimic their original interfaces. A password entered into the counterfeit wallet could then be captured by attackers, potentially enabling theft of the victim’s cryptocurrency holdings.
- MetaMask
- Coinbase Wallet
- Trust Wallet
The report covers threats identified from April through June 2026 using data collected by HP Wolf Security. It also highlights “quishing” campaigns in which emails carry PDF files presented as invoices. The information in the file is blurred, directing recipients to scan a QR code with a phone to view it.

Those QR codes can route victims through several pages before reaching a fraudulent Microsoft sign-in form intended to collect credentials. Moving the interaction from a work computer to a smartphone may help attackers bypass protections that block suspicious sites on managed desktop systems.
HP also reported continued development of Phantom Stealer, which is marketed online as a security-testing tool. Researchers identified an additional component, Phantom Gate, that facilitates malware installation and execution, making it easier to assemble attack campaigns.
Email remains the leading delivery route

Email accounted for 56% of threats detected in the reporting period, while web downloads represented 24%, HP said. Executable files made up 40% of attacker-used file types, narrowly ahead of archives at 38%.
- 56% of detected threats were delivered through email.
- 24% of detected threats came from web downloads.
- Executable files accounted for 40% of attacker-used file types.
- Archive files accounted for 38% of attacker-used file types.
- 10% of email-borne threats identified by HP Sure Click had passed at least one email-security scanner.
The finding that one in 10 email threats detected by HP Sure Click had evaded at least one scanner underlines the limits of conventional filtering. Email attachments and browser downloads remain central to attack delivery even as criminals adopt AI-themed lures and QR codes to shift targets onto mobile devices.







