• bitcoinBitcoin (BTC) $ 87,578.00
  • ethereumEthereum (ETH) $ 2,926.62
  • tetherTether (USDT) $ 0.999569
  • bnbBNB (BNB) $ 836.99
  • xrpXRP (XRP) $ 1.87
  • usd-coinUSDC (USDC) $ 0.999985
  • solanaWrapped SOL (SOL) $ 122.00
  • tronTRON (TRX) $ 0.278494
  • staked-etherLido Staked Ether (STETH) $ 2,924.86
  • dogecoinDogecoin (DOGE) $ 0.126050
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.350826
  • whitebitWhiteBIT Coin (WBT) $ 56.56
  • bitcoin-cashBitcoin Cash (BCH) $ 591.16
  • wrapped-stethWrapped stETH (WSTETH) $ 3,577.19
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 87,341.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,180.52
  • usdsUSDS (USDS) $ 0.999523
  • wrapped-eethWrapped eETH (WEETH) $ 3,172.74
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999372
  • chainlinkChainlink (LINK) $ 12.22
  • moneroMonero (XMR) $ 441.99
  • leo-tokenLEO Token (LEO) $ 8.16
  • wethWETH (WETH) $ 2,926.08
  • zcashZcash (ZEC) $ 439.87
  • stellarStellar (XLM) $ 0.211995
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 87,591.00
  • ethena-usdeEthena USDe (USDE) $ 0.998774
  • hyperliquidHyperliquid (HYPE) $ 24.61
  • litecoinLitecoin (LTC) $ 76.11
  • avalanche-2Avalanche (AVAX) $ 12.16
  • suiSui (SUI) $ 1.40
  • hedera-hashgraphHedera (HBAR) $ 0.110710
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999231
  • shiba-inuShiba Inu (SHIB) $ 0.000007
  • usdt0USDT0 (USDT0) $ 0.999051
  • paypal-usdPayPal USD (PYUSD) $ 0.998984
  • canton-networkCanton (CC) $ 0.101221
  • uniswapUniswap (UNI) $ 5.82
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.134472
  • the-open-networkToncoin (TON) $ 1.48
  • crypto-com-chainCronos (CRO) $ 0.093482
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • mantleMantle (MNT) $ 1.04
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • polkadotPolkadot (DOT) $ 1.71
  • rainRain (RAIN) $ 0.007906
  • bitget-tokenBitget Token (BGB) $ 3.45
  • memecoreMemeCore (M) $ 1.36
  • tether-goldTether Gold (XAUT) $ 4,493.38
  • aaveAave (AAVE) $ 152.10
  • okbOKB (OKB) $ 108.46
  • falcon-financeFalcon USD (USDF) $ 0.998223
  • bittensorBittensor (TAO) $ 222.00
  • nearNEAR Protocol (NEAR) $ 1.48
  • ethereum-classicEthereum Classic (ETC) $ 11.88
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,925.83
  • jito-staked-solJito Staked SOL (JITOSOL) $ 152.40
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.205751
  • pepePepe (PEPE) $ 0.000004
  • internet-computerInternet Computer (ICP) $ 3.04
  • aster-2Aster (ASTER) $ 0.683254
  • pax-goldPAX Gold (PAXG) $ 4,499.16
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • hash-2Provenance Blockchain (HASH) $ 0.032827
  • ethenaEthena (ENA) $ 0.202177
  • global-dollarGlobal Dollar (USDG) $ 0.999621
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • htx-daoHTX DAO (HTX) $ 0.000002
  • skySky (SKY) $ 0.066367
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.47
  • kucoin-sharesKuCoin (KCS) $ 10.85
  • ripple-usdRipple USD (RLUSD) $ 0.999918
  • bfusdBFUSD (BFUSD) $ 0.999089
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999712
  • midnight-3Midnight (NIGHT) $ 0.077821
  • worldcoin-wldWorldcoin (WLD) $ 0.491078
  • aptosAptos (APT) $ 1.64
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,374.27
  • binance-staked-solBinance Staked SOL (BNSOL) $ 132.85
  • gatechain-tokenGate (GT) $ 10.17
  • kaspaKaspa (KAS) $ 0.044181
  • ondo-financeOndo (ONDO) $ 0.373141
  • wbnbWrapped BNB (WBNB) $ 836.88
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.104586
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,104.76
  • quant-networkQuant (QNT) $ 73.57
  • arbitrumArbitrum (ARB) $ 0.186967
  • pump-funPump.fun (PUMP) $ 0.001749
  • algorandAlgorand (ALGO) $ 0.115500
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • official-trumpOfficial Trump (TRUMP) $ 4.94
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 87,807.00
  • ignition-fbtcFunction FBTC (FBTC) $ 87,025.00
  • cosmosCosmos Hub (ATOM) $ 1.99
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 87,515.00
  • filecoinFilecoin (FIL) $ 1.26
  • nexoNEXO (NEXO) $ 0.910565
  • vechainVeChain (VET) $ 0.010520
  • xdce-crowd-saleXDC Network (XDC) $ 0.048887
  • flare-networksFlare (FLR) $ 0.011188
  • usdtbUSDtb (USDTB) $ 0.999547
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,146.22
  • ousgOUSG (OUSG) $ 113.75
  • usddUSDD (USDD) $ 0.999341
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.94
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999694
  • beldexBeldex (BDX) $ 0.100094
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999706
  • sei-networkSei (SEI) $ 0.109277
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 87,384.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • clbtcclBTC (CLBTC) $ 87,603.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,166.73
  • render-tokenRender (RENDER) $ 1.26
  • bonkBonk (BONK) $ 0.000008
  • usdaiUSDai (USDAI) $ 0.999581
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,120.53
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999866
  • wrapped-flareWrapped Flare (WFLR) $ 0.011193
  • jupiter-exchange-solanaJupiter (JUP) $ 0.198805
  • morphoMorpho (MORPHO) $ 1.14
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.81
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,925.77
  • myx-financeMYX Finance (MYX) $ 3.22
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.81
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,084.12
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 141.26
  • curve-dao-tokenCurve DAO (CRV) $ 0.398587
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008983
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • usual-usdUsual USD (USD0) $ 0.995651
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • tbtctBTC (TBTC) $ 87,481.00
  • c8ntinuumc8ntinuum (CTM) $ 0.121180
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,926.25
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998807
  • optimismOptimism (OP) $ 0.259772
  • story-2Story (IP) $ 1.48
  • ghoGHO (GHO) $ 0.999986
  • true-usdTrueUSD (TUSD) $ 0.998253
  • merlin-chainMerlin Chain (MERL) $ 0.452581
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • dashDash (DASH) $ 38.98
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.209566
  • tezosTezos (XTZ) $ 0.452161
  • pippinpippin (PIPPIN) $ 0.475394
  • gtethGTETH (GTETH) $ 2,925.56
  • lido-daoLido DAO (LDO) $ 0.551642
  • fasttokenFasttoken (FTN) $ 1.07
  • blockstackStacks (STX) $ 0.252733
  • injective-protocolInjective (INJ) $ 4.60
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.690275
  • spx6900SPX6900 (SPX) $ 0.484201
  • ether-fiEther.fi (ETHFI) $ 0.681449
  • aerodrome-financeAerodrome Finance (AERO) $ 0.485577
  • newton-projectAB (AB) $ 0.004678
  • stader-ethxStader ETHx (ETHX) $ 3,151.04
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,139.79
  • msolMarinade Staked SOL (MSOL) $ 164.43
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.204071
  • doublezeroDoubleZero (2Z) $ 0.117080
  • usdbUSDB (USDB) $ 0.997236
  • sbtc-2sBTC (SBTC) $ 89,757.00
  • starknetStarknet (STRK) $ 0.080498
  • swethSwell Ethereum (SWETH) $ 3,222.77
  • the-graphThe Graph (GRT) $ 0.036337
  • flokiFLOKI (FLOKI) $ 0.000040
  • celestiaCelestia (TIA) $ 0.451042
  • bittorrentBitTorrent (BTT) $ 0.00000039
  • justJUST (JST) $ 0.038054
  • conflux-tokenConflux (CFX) $ 0.072764
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,271.95
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.326978
  • sun-tokenSun Token (SUN) $ 0.019449
  • bitcoin-svBitcoin SV (BSV) $ 18.59
  • ethereum-name-serviceEthereum Name Service (ENS) $ 9.45
  • euro-coinEURC (EURC) $ 1.18
  • telcoinTelcoin (TEL) $ 0.003760
  • olympusOlympus (OHM) $ 21.77
  • chilizChiliz (CHZ) $ 0.034612
  • iotaIOTA (IOTA) $ 0.083271
  • apenftAINFT (NFT) $ 0.00000035
  • kinesis-goldKinesis Gold (KAU) $ 144.88
  • pyth-networkPyth Network (PYTH) $ 0.059886
  • cap-usdCap USD (CUSD) $ 1.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 87,548.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.811679
  • kaiaKaia (KAIA) $ 0.056957
  • resolv-usrResolv USR (USR) $ 0.999676
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • usxUSX (USX) $ 0.998240
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • gnosisGnosis (GNO) $ 122.46
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.126104
  • basic-attention-tokenBasic Attention (BAT) $ 0.214844
  • dogwifcoindogwifhat (WIF) $ 0.315654

A Russian Hacking Group Is Using Fake Versions of MetaMask to Steal $1M in Crypto

0 50

A Russian Hacking Group Is Using Fake Versions of MetaMask to Steal $1M in Crypto

The Russian hacking group GreedyBear has scaled up its operations in recent months, using 150 “weaponized Firefox extensions” to target international and English-speaking victims, according to research from Koi Security.

Publishing the results of its research in a blog, U.S. and Israel-based Koi reported that the group has “redefined industrial-scale crypto theft,” using 150 weaponized Firefox extensions, close to 500 malicious executables and “dozens” of phishing websites to steal over $1 million within the past five weeks.

Speaking to Decrypt, Koi CTO Idan Dardikman said that the Firefox campaign is “by far” its most lucrative attack vector, having “gained them most of the $1 million reported by itself.”

This particular ploy involves creating fake versions of widely downloaded crypto wallets such as MetaMask, Exodus, Rabby Wallet, and TronLink.



GreedyBear operatives use Extension Hollowing to bypass marketplace security measures, initially uploading non-malicious versions of the extensions, before updating the apps with malicious code.

They also post fake reviews of the extensions, giving the false impression of trust and reliability.

But once downloaded, the malicious extensions steal wallet credentials, which in turn are used to steal crypto

Not only has GreedyBear been able to steal $1 million in just over a month using this method, but they have greatly ramped up the scale of their operations, with a previous campaign–active between April and July of this year–involving only 40 extensions.

The group’s other primary attack method involves almost 500 malicious Windows executables, which it has added to Russian websites that distribute pirated or repacked software.

Such executables include credential stealers, ransomware software and trojans, which Koi Security suggests indicates“a broad malware distribution pipeline, capable of shifting tactics as needed.”

The group has also created dozens of phishing websites, which pretend to offer legitimate crypto-related services, such as  digital wallets, hardware devices or wallet repair services.

GreedyBear uses these websites to coax potential victims into entering personal data and wallet credentials, which it then uses to steal funds.

“It is worth mentioning that the Firefox campaign targeted more global/English-speaking victims, while the malicious executables targeted more Russian-speaking victims,” explains Idan Dardikman, speaking to Decrypt.

Despite the variety of attack methods and of targets, Koi also reports that “almost all” GreedyBear attack domains link back to a single IP address: 185.208.156.66.

According to the report, this address functions as a central hub for coordination and collection, enabling GreedyBear hackers “to streamline operations.”

Dardikman saidthat a single IP address “means tight centralized control” rather than a distributed network.

“This suggests organized cybercrime rather than state sponsorship–government operations typically use distributed infrastructure to avoid single points of failure,” he added. “Likely Russian criminal groups operating for profit, not state direction.”

Dardikman said that GreedyBear is likely to continue its operations and offered several tips for avoiding their expanding reach.

“Only install extensions from verified developers with long histories,” he said, adding that users should always avoid pirated software sites.

He also recommended using only official wallet software, and not browser extensions, although he advised moving away from software wallets if you’re a serious long-term investor.

He said, “Use hardware wallets for significant crypto holdings, but only buy from official manufacturer websites–GreedyBear creates fake hardware wallet sites to steal payment info and credentials.”

Source

Leave A Reply

Your email address will not be published.