Cybercriminals in Nigeria and globally are exploiting the growing interest in artificial intelligence-powered trading agents to trick cryptocurrency users into downloading malware capable of stealing credentials from their digital wallets. According to HP's latest Wolf Security Threat Insights Report, attackers are advertising fake AI trading agents to lure crypto users into installing malicious software disguised as legitimate AI tools. This tactic has led to a new avenue for crypto theft, with attackers targeting users in Nigeria and other countries.

The malware used in these attacks scans victims' browsers for cryptocurrency wallet extensions, including Coinbase and MetaMask, before replacing legitimate extensions with malicious lookalikes designed to harvest credentials entered by users. The stolen credentials can then give attackers access to victims' cryptocurrency holdings. HP's principal threat researcher, Patrick Schläpfer, stated that attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate.

The findings highlight how cybercriminals are increasingly adapting their tactics to emerging technologies and popular online trends rather than relying solely on conventional phishing emails or malicious downloads. HP said the fake AI trading-agent campaign is part of a broader pattern in which attackers are developing more specialised tools and infection methods to make cyberattacks easier to deploy and scale. This trend is also observed in Nigeria, where cybercrime is on the rise.

Researchers also identified Phantom Gate, a new malware loader that appears to extend the existing Phantom Stealer campaign. Phantom Stealer is openly marketed as legitimate penetration-testing software, but HP said its combination with the Phantom Gate loader makes it easier for threat actors to build and scale attack campaigns. This development points to a more modular cybercrime ecosystem in which attackers can combine different malicious components.

The HP report also identified the continued use of QR codes as a route for credential theft. In one tactic, attackers send victims PDFs containing content supposedly "blurred for security" and instruct them to scan a QR code using their smartphones. The QR code then redirects users to phishing websites that may not have been blocked on their computers. This tactic allows attackers to move victims from PCs to mobile devices, where security protections may be weaker.

The findings show that cybercriminals are increasingly exploiting the way users move between devices, applications, and emerging technologies. HP's research found that at least 10 percent of email threats identified by its HP Sure Click technology bypassed one or more email gateway scanners between April and June 2026. Executable files accounted for 40 percent of malware delivery during the period, making them the most common delivery format.

HP recommends integrating isolation and containment into a zero-trust security approach so that untrusted clicks and downloads do not automatically result in endpoint compromises. As AI tools become increasingly embedded in financial services, trading, and everyday digital activity, the latest findings suggest cybercriminals are also moving quickly to exploit the technology's popularity in Nigeria and globally.

Key points

  • Cybercriminals are using AI trading hype to trick cryptocurrency users into downloading malware that steals credentials from digital wallets.
  • The malware used in these attacks scans victims' browsers for cryptocurrency wallet extensions and replaces legitimate extensions with malicious lookalikes.
  • HP recommends integrating isolation and containment into a zero-trust security approach to prevent endpoint compromises.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.