By using this site, you agree to the Privacy Policy..
Accept
Latest cryptocurrency newsLatest cryptocurrency newsLatest cryptocurrency news
  • BITCOIN
  • Crypto Tracker App
  • ETHEREUM
  • RIPPLE
  • Crypto News
  • FINANCE NEWS
  • BLOCKCHAIN
  • CONTACT
  • TURKISHTURKISHTURKISH
Reading: New Threat Looms Over Crypto Users as Torg Grabber Strikes
Share
Font ResizerAa
Latest cryptocurrency newsLatest cryptocurrency news
Font ResizerAa
  • BITCOIN
  • Crypto Tracker App
  • ETHEREUM
  • RIPPLE
  • Crypto News
  • FINANCE NEWS
  • BLOCKCHAIN
  • CONTACT
  • TURKISHTURKISHTURKISH
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> BH NEWS.
Powered By LK SOFTWARE
Latest cryptocurrency news > BLOCKCHAIN > New Threat Looms Over Crypto Users as Torg Grabber Strikes
BLOCKCHAIN

New Threat Looms Over Crypto Users as Torg Grabber Strikes

BH NEWS
Last updated: 27 March 2026 11:46
BH NEWS 4 weeks ago
Share
SHARE

Contents
How Does Torg Grabber Operate?Who Is Most At Risk?

A potent new malware, Torg Grabber, is putting digital assets and cryptocurrency wallets at significant risk by targeting browser extensions connected to crypto holdings. The software is currently active, threatening the security of 728 browser-based crypto wallet extensions among more than 850 targeted plugins. This poses an immediate danger to numerous digital wallets.

How Does Torg Grabber Operate?

Torg Grabber begins its attack through an installation package known as GAPI_Update.exe. This 60 MB InnoSetup file uses Dropbox infrastructure to infiltrate victim computers, discreetly placing three DLL files in the local directory and prompting a fake Windows Security Update screen. During this decoy process, which lasts 420 seconds, the malware loads itself unnoticed in the background, fooling users into thinking a legitimate update is occurring.

Once Torg Grabber is installed, it plants randomly named executable files into the Windows directory, trying to alter event logging systems to avoid detection. Despite these attempts, behavioral analysis solutions have successfully thwarted further damage. The malware’s scope extends beyond popular browsers, encompassing 25 Chromium-based browsers, 8 Firefox variants, and popular applications like Discord, Steam, and Telegram.

Who Is Most At Risk?

The greatest threat is to those managing cryptocurrency through browser-based wallets like MetaMask and Phantom. These users could lose their complete balances if their credentials are compromised. Even hardware wallet users are not entirely safe if they keep recovery phrases digitally on infected systems.

In an exhaustive analysis by cybersecurity experts Gen Digital, Torg Grabber was found to have 334 distinct variants within three months, pointing to a substantial Malware-as-a-Service operation rather than an isolated incident. The investigation identified nearly 40 operator tags and other markers linked to Russian cybercrime networks, highlighting the scale of this criminal endeavor.

The primary goal of the malware is to access locally stored wallet files and session tokens, opening avenues for unauthorized fund transfers from logged-in cryptocurrency exchanges.

Despite employing established techniques from past malware like Vidar and RedLine, Torg Grabber’s sophisticated infrastructure and increasing list of targeted wallet extensions make it a formidable threat. Its ability to scan 728 distinctive wallets simultaneously sets a worrying benchmark that could escalate as the malware continues to develop.

“Investigators have emphasized that Torg Grabber targets 728 cryptocurrency wallets, enabling the theft of sensitive user data and driving financially motivated attacks.”

To protect against such sophisticated threats:
– Ensure crypto assets are managed with secure, updated tools.
– Always verify software downloads come from trustworthy sources.
– Regularly back up crucial wallet information offline.

As Torg Grabber prowls the digital sphere, it’s crucial for crypto users to remain vigilant, employing robust security measures to combat this evolving threat. Enhanced awareness and preventive actions are key to safeguarding digital assets from such sophisticated cyber incursions.

You can follow our news on Telegram and Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Nexera Burns 32.5 Million Tokens

Unexpected Block Production Halt in ZKSync Era Raises Questions

HSBC Pioneers Gold Tokenization for Retail Investors in Hong Kong

Kyrgyzstan Moves Forward with Digital Currency Initiative

TON Network Outpaces Ethereum Daily

Share This Article
Facebook X Email Print
Previous Article US Senate’s New Crypto Bill Faces Roadblocks from Major Exchange
Next Article Tether Appoints Audit Giant for In-Depth Review of Reserves
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stability Meets Oversight as Major Crypto Firm Freezes USDT
Tether (USDT)
Heightened Tensions Shake Markets as Naval Strategies Unfold
Cryptocurrency
US Military Operates Bitcoin Node, Boosts Network Security Research
Cryptocurrency
FTX Founder Stuns Court with Unexpected Move
Cryptocurrency Law
Solana Mobile Token Faces Notable Dip: What’s Next?
Solana (SOL)
Bitcoin Moves: A New Era for Institutional Strategies
BITCOIN (BTC)

CRYPTOCURRENCIES

  • Avalanche (AVAX)
  • Cardano (ADA)
  • CHAINLINK (LINK)
  • Solana (SOL)
about us

Stay informed with BH NEWS, your trusted source for the latest cryptocurrency news, trends, and analysis. From market updates to blockchain innovations, we deliver the insights you need to navigate the world of digital assets confidently.

OUR PARTNERS

  • COINTURK NEWS
  • NEWSLINKER
  • 21MILYON
  • COINTURK

Corporate

  • About Us
  • Cookie Policy
  • Contact

Find Us on Socials

© 2026 BH NEWS.
Powered By LK SOFTWARE
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?