216.73.216.226

Needle: Inside a Modular Crypto-Stealing C2 That Left Its Keys in the Malware

· Published 11/05/2026 08:50 · Modified 11/05/2026 09:56

Export JSON

Essential information

Published
11/05/2026 08:50
Modified
11/05/2026 09:56
Tags
2026-05-11 bulletproof hosting crypto-stealer cryptocurrency theft maas needle phorpiex rustystealer wallet-spoofer
Related entities
1 observables, 19 techniques (mitre), 2 malware

Description

A modular Malware-as-a-Service crypto-stealing platform called has been discovered actively targeting cryptocurrency wallets through two main attack vectors: a browser extension spoofer targeting MetaMask, Phantom, and Trust Wallet, and a Rust-based desktop agent impersonating Exodus, Trezor, and Ledger applications. The campaign compromised 1,932 victims, including 111 browser extension users and 1,821 desktop sessions. The Rust agent embedded its C2 API key without protection, enabling complete enumeration of victims and withdrawal configurations across six blockchains. The operator's EVM hot wallet moved approximately $148 in ETH to cold storage. The panel's React SPA performed authentication entirely client-side, and the same credential used by infected machines could potentially redirect future auto-withdrawals. Infrastructure is hosted on ASN 202412, a known provider in Amsterdam.

External references