A group of Russian hackers is using a fake version of MetaMask to steal 1 million dollars in cryptocurrency.

The Russian hacker group GreedyBear has expanded its operations, using 150 malicious Firefox extensions, nearly 500 dangerous executable files, and dozens of phishing websites, stealing over 1 million USD in just 5 weeks, according to Koi Security. The Firefox campaign is the most lucrative attack channel, impersonating MetaMask, Exodus, Rabby Wallet, and TronLink wallets. The group utilizes the Extension Hollowing technique to bypass censorship, then installs malware to steal wallet information. Additionally, they spread malware through illegal software sharing sites and create fake cryptocurrency service websites to deceive users. Most of the attack domains link to a single IP address, indicating that this is an organized cybercrime activity. Koi recommends only installing extensions from reputable sources, avoiding illegal software, and using genuine hardware wallets to protect assets.

LA0.54%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 3
  • Repost
  • Share
Comment
0/400
GateUser-720cce0bvip
· 14h ago
HODL Tight 💪
Reply0
GateUser-8bca5a99vip
· 22h ago
Ape In 🚀
Reply0
GateUser-8bca5a99vip
· 22h ago
Bull Run 🐂
Reply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)