Cybercriminals Steal $1M via 150 Malicious Firefox Crypto Wallet Extensions
– Russian cybercriminal group GreedyBear stole $1M via 150 malicious Firefox extensions mimicking crypto wallets like MetaMask and Exodus.
– They bypassed Firefox security reviews using “Extension Hollowing,” submitting benign versions before updating with malware to steal credentials.
– The group also deployed 500 malicious Windows executables and phishing sites, targeting English and Russian speakers through centralized IP 185.208.156.66.
– Koi Security warns against untrusted extensions and recommends hardware wallets from official sites to mitigate risks from such industrial-scale theft.
– The attack highlights vulnerabilities in crypto ecosystems, urging stronger authentication and multi-signature setups to combat evolving cyber…