• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

New ‘Torg Grabber’ Malware Targets 728 Crypto Wallets

March 27, 2026
in Crypto News
Reading Time: 4min read
0 0
A A
0
Bitcoin Price Prediction: Florida’s Crypto Bill and $198B U.S. Surplus Boost Market Outlook
0
SHARES
5
VIEWS
ShareShareShareShareShare

Torg Grabber, a newly identified infostealer malware, targets 728 crypto wallet extensions across 850 browser add-ons, and it is already in active deployment.

The malware exfiltrates seed phrases, private keys, and session tokens through encrypted channels before most endpoint tools register a detection event. Self-custody users running browser-based wallets are the primary exposure surface.

Gen Digital researchers documented the threat after tracing a loader chain through domain reputation data, ultimately compiling 334 samples across a three-month development window. This is not a proof-of-concept. It is a live Malware-as-a-Service operation with identified operators.

Key Takeaways:

  • Threat Scope: Torg Grabber scans 850 browser extensions, 728 of them crypto wallet targets, across 25 Chromium and 8 Firefox browser variants.
  • Attack Method: Dropper masquerades as a legitimate Chrome update (GAPI_Update.exe, 60 MB), deploys payload via a fake 420-second Windows Security Update progress bar, then exfiltrates data using ChaCha20 encryption with HMAC-SHA256 authentication through Cloudflare infrastructure.
  • Who Is at Risk: Browser-extension wallet users — MetaMask, Phantom, and comparable hot wallets — face direct credential theft; hardware wallet users face indirect risk only if seed phrases are stored digitally.

Discover: The best crypto presales gaining institutional momentum right now

The Mechanism: How Torg Grabber Malware Executes the Attack On Crypto Wallets

The infection chain opens with a dropper disguised as GAPI_Update.exe — a 60 MB InnoSetup package distributed from Dropbox infrastructure. It extracts three benign DLLs into %LOCALAPPDATA%\Connector\ to establish a clean-looking footprint, then launches a fake Windows Security Update progress bar running for exactly 420 seconds, complete with animated ASCII art compiled via csc.exe. The delay is deliberate: it creates a plausible installation window while the payload deploys.

The final executable drops under randomized names — v4jkqh.exe, hkjpy08.exe, ln3dkgz.exe — into C:\Windows\ across documented samples. One captured 13 MB instance spawned dllhost.exe and attempted to disable Event Tracing for Windows before behavioral detection terminated it mid-execution.

Post-deployment, Torg Grabber targets 25 Chromium browsers, 8 Firefox variants, Discord, Steam, Telegram, VPN clients, FTP clients, email clients, and password managers in addition to crypto wallets. Data is archived to an in-memory ZIP or streamed in chunks. Exfiltration routes through Cloudflare endpoints using per-request HMAC-SHA256 X-Auth-Token headers and ChaCha20 encryption — a production-grade architecture, not improvised tooling.

CRYPTO THEFT MALWARE: New “Torg Grabber” infostealer targets 728 cryptocurrency wallets.

The malware is designed to harvest wallet data and enable theft of digital assets.

Crypto wallets remain a primary target for financially motivated attackers.

— CyberAlertsHQ (@CyberAlertsHQ) March 25, 2026

Gen Digital’s analysis identified over 40 operator tags embedded in binaries: nicknames, date-encoded batch IDs, and Telegram user IDs linking eight operators to the Russian cybercrime ecosystem. The MaaS model means individual operators can deploy custom shellcode post-registration, expanding the attack surface beyond the base configuration. As Gen Digital researchers described it, Torg Grabber evolved from Telegram dead drops to “a production-grade REST API that worked like a Swiss watch dipped in poison.”

Discover: The best crypto to diversify your portfolio with

The Self-Custody Signal: What 728 Wallets Actually Means

728 is not an arbitrary number. It represents a deliberate configuration sweep, every major browser-based wallet with measurable installation volume. MetaMask alone has over 30 million monthly active users. The extension-targeting logic means Torg Grabber does not need to find a specific victim; it harvests whatever wallet credentials are present on any infected machine.

The broader risk bifurcates cleanly. Self-custody users storing seed phrases in browser storage, text files, or password managers face complete wallet compromise on a single infection. Exchange-held assets are not directly exposed to this specific attack vector, the malware targets local credential stores, not exchange APIs at scale. But session token theft from browser storage can expose connected exchange accounts if login sessions are active.

If Torg Grabber’s MaaS operator base expands, and Gen Digital’s monitoring of its REST API infrastructure suggests active iteration, the wallet targeting list will grow. The 728 figure is a current snapshot, not a ceiling. Comparable infostealers like Vidar and RedLine normalized this model years ago; Torg Grabber is executing the same playbook with more structured infrastructure.

Discover: The best crypto presales gaining institutional momentum right now

The post New ‘Torg Grabber’ Malware Targets 728 Crypto Wallets appeared first on Cryptonews.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Startale Group Raises $63 Million Series A Backed by SBI and Sony

Next Post

Analyst Warns Downtrend Won’t Be Over Soon

Next Post
What Made Solana Memecoins The Cycle’s Top Narrative

Analyst Warns Downtrend Won’t Be Over Soon

You might also like

Strive Seeks $4.2B ATM Expansion To Fund More Bitcoin Buys

Strive Adds 759 Bitcoin As Corporate BTC Treasury Race Continues

June 22, 2026
Bitcoin Bears Eye Lower Levels As TradingView Analysts Flag

Bitcoin Bears Eye Lower Levels As TradingView Analysts Flag

June 21, 2026
BOJ Raises Rates To 1% As Crypto Traders Watch Yen Carry Risk

SBI And Startale Put Yen Stablecoins Back In The Institutional Spotlight

June 24, 2026
Stablecoin Supply Rises To $315B As Institutional Flows Lift USDC

ICE And OKX Tokenized Equities Venture Shows Wall Street Moving On-Chain

June 25, 2026
Is The Senate Finally Pulling the Plug on Trump Crypto Activities?

Is The Senate Finally Pulling the Plug on Trump Crypto Activities?

June 24, 2026
Why Is Crypto Up Today? – October 15, 2025

XRP Price Prediction: Ripple Secures Preliminary Luxembourg CASP Approval

June 23, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Bitcoin holds near $59.9K as Polymarket prices 99% odds above $54K

Bitcoin holds near $59.9K as Polymarket prices 99% odds above $54K

June 28, 2026
Trump-Iran war deal nudges Israel PM market, Eizenkot leads at 38.55%

Letlow primary win shifts Iran-entry market as Polymarket puts Senators at 55%

June 28, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.