New virus captures information from hundreds of cryptocurrency wallets — Gen Digital, 2026/03/28 12:31:27

29

Новый вирус перехватывает данные сотен криптокошельков — Gen Digital0

Experts from the cybersecurity firm Gen Digital have reported on the malware Torg Grabber, which is capable of stealing information from 728 browser-based cryptocurrency wallets, including Phantom, Trust Wallet, and MetaMask.

According to the specialists, the infection occurs through a technique known as ClickFix. Cybercriminals intercept the clipboard and trick the user into executing a malicious command that activates the virus.

Torg Grabber also extracts information from various applications, including messaging platforms (such as Discord and Telegram), gaming services, VPN clients, and email providers.

Analysts note that the operators of the malware utilize a secure connection via Cloudflare’s infrastructure and have modified the virus to bypass protective measures in browsers like Google Chrome, Brave, Microsoft Edge, Vivaldi, and Opera. The program is designed to steal passwords, private keys, seed phrases, and session data.

Experts have advised keeping significant amounts of cryptocurrency outside of hot wallets and limiting the use of desktop solutions for transactions involving large sums.

Previously, specialists from Kaspersky Lab reported on the malware Stealka, which steals passwords for cryptocurrency wallets and banking card information on devices running Windows.