Security researchers have uncovered Torg Grabber, a malware strain designed to compromise 728 crypto wallet extensions simultaneously. The threat extends beyond browsers, also targeting password managers, VPN clients, and messaging apps like Telegram and Discord.
Multi-Stage Infection via Fake Windows Update
The attack chain starts with a 60 MB installer named GAPI_Update.exe, built with InnoSetup and delivered through Dropbox. Once executed, it drops three innocuous-looking DLL files and displays a decoy Windows Security Update screen for 420 seconds, keeping users occupied while the malware loads in the background.
After installation, randomly named executables appear in the Windows directory. Samples have been observed interfering with system event logging to hide their presence. Behavioral analysis tools have foiled some attempts, limiting further damage.
Scope: 25 Chromium Browsers, 8 Firefox Variants, and Key Apps
Torg Grabber targets 25 Chromium-based browsers, eight Firefox variants, plus widely used applications such as Steam, Discord, and Telegram. Password vaults, VPN clients, FTP tools, and email clients are also on the list. Stolen data is either compressed on the fly or exfiltrated in chunks, routed through Cloudflare with ChaCha20 encryption and HMAC-SHA256 authentication — a sign of a sophisticated, service-based criminal operation rather than a simple script.
Hot Wallet Users at Highest Risk
Users managing crypto via browser-based hot wallets like MetaMask and Phantom face the greatest danger. If private keys or encryption keys reside on the local machine, a single breach can drain the entire balance. Hardware wallet holders are not safe either if they store recovery phrases in any digital format on the infected device.
334 Variants in Three Months, Russian Cybercrime Links
Cybersecurity firm Gen Digital tracked 334 distinct variants of Torg Grabber over three months, concluding it is an active Malware-as-a-Service campaign. Embedded information revealed nearly 40 operator tags, version codes, and Telegram handles. Evidence points to at least eight criminal actors, many connected to Russia’s cybercrime ecosystem.
The malware targets locally stored wallet files, backup copies, and session tokens from logged-in exchange sessions. While sharing techniques with older malware like Vidar and RedLine, Torg Grabber benefits from a more advanced infrastructure and an ever-expanding target list — setting a new benchmark for crypto-focused attacks.

