{"id":179441,"date":"2026-03-27T11:20:11","date_gmt":"2026-03-27T11:20:11","guid":{"rendered":"https:\/\/cryptonews.com\/fr\/news\/le-nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/"},"modified":"2026-03-27T11:20:14","modified_gmt":"2026-03-27T11:20:14","slug":"nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/","title":{"rendered":"Le nouveau malware &#171;&nbsp;Torg Grabber&nbsp;&#187; cible 728 portefeuilles crypto"},"content":{"rendered":"<p>Torg Grabber, un malware de type \u00ab infostealer \u00bb r\u00e9cemment identifi\u00e9, cible 728 extensions de portefeuilles crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif.<\/p><p>Le malware exfiltre les phrases de r\u00e9cup\u00e9ration (seed phrases), les cl\u00e9s priv\u00e9es et les jetons de session via des canaux chiffr\u00e9s avant que la plupart des outils de protection des points de terminaison ne d\u00e9tectent l&#8217;\u00e9v\u00e9nement. Les utilisateurs en auto-conservation (self-custody) utilisant des portefeuilles bas\u00e9s sur navigateur constituent la principale surface d&#8217;exposition.<\/p><p>Les chercheurs de <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/torg-grabber-credential-stealer-analysis\" target=\"_blank\" rel=\"noreferrer noopener\">Gen Digital<\/a> ont document\u00e9 la menace apr\u00e8s avoir trac\u00e9 une cha\u00eene de chargement via des donn\u00e9es de r\u00e9putation de domaine, compilant finalement 334 \u00e9chantillons sur une p\u00e9riode de d\u00e9veloppement de trois mois.<\/p><p>Il ne s&#8217;agit pas d&#8217;une preuve de concept, mais d&#8217;une op\u00e9ration active de Malware-as-a-Service (MaaS) avec des op\u00e9rateurs identifi\u00e9s.<\/p><div class=\"su-note\" style=\"border: 1px solid #e0d5e5; border-radius: 5px; margin: 20px 0; background-color: #faefff; color: #333333; padding: 20px;\"><strong>Points cl\u00e9s :<\/strong>\n<ul>\n<li><strong>Port\u00e9e de la menace :<\/strong> Torg Grabber analyse 850 extensions de navigateur, dont 728 portefeuilles crypto cibles, sur 25 variantes de navigateurs Chromium et 8 variantes de Firefox.<\/li>\n<li><strong>M\u00e9thode d&#8217;attaque :<\/strong> Le dropper se fait passer pour une mise \u00e0 jour l\u00e9gitime de Chrome (GAPI_Update.exe, 60 Mo), d\u00e9ploie la charge utile via une fausse barre de progression de mise \u00e0 jour de s\u00e9curit\u00e9 Windows de 420 secondes, puis exfiltre les donn\u00e9es en utilisant le chiffrement ChaCha20 avec authentification HMAC-SHA256 via l&#8217;infrastructure Cloudflare.<\/li>\n<li><strong>Qui est \u00e0 risque :<\/strong> Les utilisateurs de portefeuilles en extension de navigateur \u2014 MetaMask, Phantom et autres hot wallets comparables \u2014 font face \u00e0 un vol direct d&#8217;identifiants ; les utilisateurs de portefeuilles physiques (hardware wallets) ne courent un risque indirect que si leurs phrases de r\u00e9cup\u00e9ration sont stock\u00e9es num\u00e9riquement.<\/li>\n<\/ul>\n<\/div><p><strong><a href=\"https:\/\/cryptonews.com\/fr\/cryptomonnaie\/cryptos-qui-vont-exploser\/\" target=\"_blank\" rel=\"noreferrer noopener sponsored nofollow\">D\u00e9couvrez : Les meilleures cryptos qui pourraient exploser<\/a><\/strong><\/p><h2 class=\"wp-block-heading\">Le m\u00e9canisme : comment le malware Torg Grabber ex\u00e9cute l&#8217;attaque sur les portefeuilles crypto<\/h2><p><span class=\"replacer\"><\/span><br>\nLa cha\u00eene d&#8217;infection commence par un dropper d\u00e9guis\u00e9 en GAPI_Update.exe \u2014 un package InnoSetup de 60 Mo distribu\u00e9 depuis l&#8217;infrastructure Dropbox.<\/p><p>Il extrait trois DLL b\u00e9nignes dans <code>%LOCALAPPDATA%\\Connector\\<\/code> pour \u00e9tablir une empreinte d&#8217;apparence propre, puis lance une fausse barre de progression de mise \u00e0 jour de s\u00e9curit\u00e9 Windows durant exactement <strong>420 secondes<\/strong>, compl\u00e9t\u00e9e par un art ASCII anim\u00e9 compil\u00e9 via csc.exe. Ce d\u00e9lai est d\u00e9lib\u00e9r\u00e9 : il cr\u00e9e une fen\u00eatre d&#8217;installation plausible pendant que la charge utile se d\u00e9ploie.<\/p><p>L&#8217;ex\u00e9cutable final est d\u00e9pos\u00e9 sous des noms al\u00e9atoires \u2014 v4jkqh.exe, hkjpy08.exe, ln3dkgz.exe \u2014 dans C:\\Windows\\ selon les \u00e9chantillons document\u00e9s. Une instance de 13 Mo captur\u00e9e a engendr\u00e9 dllhost.exe et a tent\u00e9 de d\u00e9sactiver l&#8217;Event Tracing de Windows avant qu&#8217;une d\u00e9tection comportementale ne mette fin \u00e0 son ex\u00e9cution.<\/p><p>Apr\u00e8s le d\u00e9ploiement, Torg Grabber cible 25 navigateurs Chromium, 8 variantes de Firefox, Discord, Steam, Telegram, des clients VPN, des clients FTP, des clients de messagerie et des gestionnaires de mots de passe en plus des portefeuilles crypto.<\/p><p>Les donn\u00e9es sont archiv\u00e9es dans un ZIP en m\u00e9moire ou diffus\u00e9es par blocs. L&#8217;exfiltration transite par des points de terminaison Cloudflare en utilisant des en-t\u00eates X-Auth-Token HMAC-SHA256 par requ\u00eate et un chiffrement ChaCha20 \u2014 une architecture de niveau professionnel, et non un outil improvis\u00e9.<\/p><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\ud83d\udea8 CRYPTO THEFT MALWARE: New \u201cTorg Grabber\u201d infostealer targets 728 cryptocurrency wallets.<\/p>\n<p>The malware is designed to harvest wallet data and enable theft of digital assets.<\/p>\n<p>Crypto wallets remain a primary target for financially motivated attackers.<\/p>\n<p>&mdash; CyberAlertsHQ (@CyberAlertsHQ) <a href=\"https:\/\/twitter.com\/CyberAlertsHQ\/status\/2036949002575614362?ref_src=twsrc%5Etfw\">March 25, 2026<\/a><\/p><\/blockquote><p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p><p>L&#8217;analyse de Gen Digital a identifi\u00e9 plus de 40 balises d&#8217;op\u00e9rateurs int\u00e9gr\u00e9es dans les binaires : pseudos, identifiants de lots encod\u00e9s par date et identifiants d&#8217;utilisateurs Telegram reliant huit op\u00e9rateurs \u00e0 l&#8217;\u00e9cosyst\u00e8me de la cybercriminalit\u00e9 russe.<\/p><p>Le mod\u00e8le MaaS signifie que les op\u00e9rateurs individuels peuvent d\u00e9poy\u00e9r du shellcode personnalis\u00e9 apr\u00e8s l&#8217;enregistrement, \u00e9largissant la surface d&#8217;attaque au-del\u00e0 de la configuration de base.<\/p><p>Comme l&#8217;ont d\u00e9crit les chercheurs de Gen Digital, Torg Grabber a \u00dfvolu\u00e9 des points de d\u00e9p\u00f4t Telegram vers \u00ab une API REST de qualit\u00e9 industrielle fonctionnant comme une montre suisse tremp\u00e9e dans le poison \u00bb.<\/p><h2 class=\"wp-block-heading\">Le signal de l&#8217;auto-conservation : ce que signifient r\u00e9ellement 728 portefeuilles<\/h2><p><span class=\"replacer\"><\/span><br>\n728 n&#8217;est pas un nombre arbitraire. Il repr\u00e9sente un balayage de configuration d\u00e9lib\u00e9r\u00e9, incluant chaque portefeuille majeur bas\u00e9 sur navigateur avec un volume d&#8217;installation mesurable. MetaMask compte \u00e0 lui seul plus de 30 millions d&#8217;utilisateurs actifs mensuels.<\/p><p>La logique de ciblage des extensions signifie que Torg Grabber n&#8217;a pas besoin de trouver une victime sp\u00e9cifique ; il r\u00e9cup\u00e8re tous les identifiants de portefeuille pr\u00e9sents sur n&#8217;importe quelle machine infect\u00e9e.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-491845\" src=\"https:\/\/cimg.co\/wp-content\/uploads\/2026\/03\/26140049\/image-207.jpg\" alt=\"\" width=\"700\" height=\"650\"><\/figure><p>Le risque global se divise nettement en deux. Les utilisateurs en auto-conservation stockant des phrases de r\u00e9cup\u00e9ration dans le stockage du navigateur, des fichiers texte ou des gestionnaires de mots de passe s&#8217;exposent \u00e0 une compromission totale du portefeuille d\u00e8s une seule infection.<\/p><p>Les actifs d\u00e9tenus sur des plateformes d&#8217;\u00e9change ne sont pas directement expos\u00e9s \u00e0 ce vecteur d&#8217;attaque sp\u00e9cifique, le malware ciblant les stockages d&#8217;identifiants locaux et non les API des plateformes \u00e0 grande \u00e9chelle. Cependant, le vol de jetons de session peut exposer les comptes d&#8217;\u00e9change connect\u00e9s si les sessions de connexion sont actives.<\/p><p>Si la base d&#8217;op\u00e9rateurs MaaS de Torg Grabber s&#8217;\u00e9tend \u2014 et la surveillance de son infrastructure API REST par Gen Digital sugg\u00e8re une it\u00e9ration active \u2014, la liste des portefeuilles cibles s&#8217;allongera. Le chiffre de 728 est un instantan\u00e9 actuel, pas un plafond. Des infostealers comparables comme Vidar et RedLine ont normalis\u00e9 ce mod\u00e8le il y a des ann\u00e9es ; Torg Grabber ex\u00e9cute la m\u00eame strat\u00e9gie avec une infrastructure plus structur\u00e9e.<\/p>","protected":false},"excerpt":{"rendered":"<p>Le malware Torg Grabber cible 728 portefeuilles crypto<\/p>\n","protected":false},"author":605,"featured_media":179440,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"editors":[2551],"sponsored_companies":[],"class_list":["post-179441","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","editors-julien-leroy"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Le nouveau malware Torg Grabber cible 728 portefeuilles crypto<\/title>\n<meta name=\"description\" content=\"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto\" \/>\n<meta property=\"og:description\" content=\"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-27T11:20:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-27T11:20:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"686\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto\" \/>\n<meta name=\"twitter:description\" content=\"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto","description":"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/","og_locale":"fr_FR","og_type":"article","og_title":"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto","og_description":"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif","og_url":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/","og_site_name":"Cryptonews France","article_published_time":"2026-03-27T11:20:11+00:00","article_modified_time":"2026-03-27T11:20:14+00:00","og_image":[{"width":1200,"height":686,"url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto","twitter_description":"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif","twitter_image":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/"},"author":{"name":"Julien Leroy","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/f59ffc7902f955612739e25fdd52da26"},"headline":"Le nouveau malware &#171;&nbsp;Torg Grabber&nbsp;&#187; cible 728 portefeuilles crypto","datePublished":"2026-03-27T11:20:11+00:00","dateModified":"2026-03-27T11:20:14+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/"},"wordCount":959,"commentCount":0,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","articleSection":["News"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#respond"]}],"copyrightYear":"2026","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/","url":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/","name":"Le nouveau malware Torg Grabber cible 728 portefeuilles crypto","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","datePublished":"2026-03-27T11:20:11+00:00","dateModified":"2026-03-27T11:20:14+00:00","description":"Torg Grabber, malware infostealer, cible 728 extensions de wallet crypto parmi 850 add-ons de navigateurs, et son d\u00e9ploiement est d\u00e9j\u00e0 actif","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#primaryimage","url":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","contentUrl":"https:\/\/cimg.co\/wp-content\/uploads\/sites\/3\/2026\/03\/27082908\/1744184088-image-1727082450955_optimized.jpg","width":1200,"height":686},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/nouveau-malware-torg-grabber-cible-728-portefeuilles-crypto\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Le nouveau malware &#171;&nbsp;Torg Grabber&nbsp;&#187; cible 728 portefeuilles crypto"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/179441","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/605"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=179441"}],"version-history":[{"count":1,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/179441\/revisions"}],"predecessor-version":[{"id":179454,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/179441\/revisions\/179454"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media\/179440"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=179441"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=179441"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=179441"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=179441"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=179441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}