New Torg Grabber infostealer malware targets 728 crypto wallets
2026-03-25T19:23:35Z•88c7765c1f87ff17d678c2d36596a1b741261c42e4204e65b6b0691addff18a6
backdoorbrowser-extensionsbuilt-in-vpn','outlook-sync-fix','zero-trust','hackerone','naviacitrixcredential-theftcrypto-walletsfccfirefoxfirmware-uploadflexplminfostealerlitellmnetscalerptcpypircerouter-auth-bypassrouter-bansupply-chainteampcptorg-grabbertp-linkvulnerabilitieswindchillzero-day-like
What happened
BleepingComputer roundup (25 Mar 2026): A new infostealer dubbed “Torg Grabber” is stealing data from ~850 browser extensions — including 728 crypto-wallet extensions — putting users' wallets and credentials at high risk. Multiple high-impact vulnerabilities were disclosed/patched: Citrix patched two NetScaler ADC/Gateway flaws (noted as similar to prior CitrixBleed exploits), TP‑Link fixed a critical authentication-bypass in Archer NX routers that could allow firmware uploads, and PTC warned of an imminent critical RCE in Windchill and FlexPLM. Supply-chain and credential-theft activity escal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 88c7765c1f87ff17d678c2d36596a1b741261c42e4204e65b6b0691addff18a6
- Enrichment time
- 2026-03-25T19:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.