New Torg Grabber infostealer malware targets 728 crypto wallets

2026-03-25T19:23:35Z88c7765c1f87ff17d678c2d36596a1b741261c42e4204e65b6b0691addff18a6
backdoorbrowser-extensionsbuilt-in-vpn','outlook-sync-fix','zero-trust','hackerone','naviacitrixcredential-theftcrypto-walletsfccfirefoxfirmware-uploadflexplminfostealerlitellmnetscalerptcpypircerouter-auth-bypassrouter-bansupply-chainteampcptorg-grabbertp-linkvulnerabilitieswindchillzero-day-like

What happened

BleepingComputer roundup (25 Mar 2026): A new infostealer dubbed “Torg Grabber” is stealing data from ~850 browser extensions — including 728 crypto-wallet extensions — putting users' wallets and credentials at high risk. Multiple high-impact vulnerabilities were disclosed/patched: Citrix patched two NetScaler ADC/Gateway flaws (noted as similar to prior CitrixBleed exploits), TP‑Link fixed a critical authentication-bypass in Archer NX routers that could allow firmware uploads, and PTC warned of an imminent critical RCE in Windchill and FlexPLM. Supply-chain and credential-theft activity escal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
88c7765c1f87ff17d678c2d36596a1b741261c42e4204e65b6b0691addff18a6
Enrichment time
2026-03-25T19:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Torg Grabber infostealer malware targets 728 crypto wallets · Baitaphish