Over 700 browser crypto wallets targeted by infostealer


The new infostealer Torg Grabber is aimed at confidential information from 850 browser extensions. Among them are cryptocurrency wallets, password managers, note-taking apps, and two-factor authentication tools. Initial access to the system is achieved using ClickFix technique: attackers intercept the clipboard and trick the user into executing a malicious PowerShell command. Torg Grabber also collects data from Discord, Telegram, Steam, VPN tools, email services, and desktop versions of crypto applications.

In addition to the listed capabilities, the malware can:

create a digital fingerprint of the device;
analyze installed software (including 24 antivirus programs);
take screenshots of the desktop;
steal files from "Desktop" and "Documents" folders;
execute arbitrary code on the infected device.
Since the end of 2025, scammers have been using a more efficient HTTPS connection through Cloudflare infrastructure. They have taught the stealer to bypass cookie protection in Chrome, Brave, Edge, Vivaldi, and Opera.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin