Cybercriminals Steal $1M via 150 Malicious Firefox Crypto Wallet Extensions

– Russian cybercriminal group GreedyBear stole $1M via 150 malicious Firefox extensions mimicking crypto wallets like MetaMask and Exodus.

– They bypassed Firefox security reviews using “Extension Hollowing,” submitting benign versions before updating with malware to steal credentials.

– The group also deployed 500 malicious Windows executables and phishing sites, targeting English and Russian speakers through centralized IP 185.208.156.66.

– Koi Security warns against untrusted extensions and recommends hardware wallets from official sites to mitigate risks from such industrial-scale theft.

– The attack highlights vulnerabilities in crypto ecosystems, urging stronger authentication and multi-signature setups to combat evolving cyber…

Source link