Bitprismia

GreedyBear Hackers Steal $1M+ in ‘Industrial Scale’ Crypto Theft Using Multi-Vector Attack

2025-08-08 07:24:09

Main Idea

The GreedyBear hacker group stole over $1 million in cryptocurrency using a sophisticated operation involving 150 weaponized Firefox extensions and a novel 'Extension Hollowing' technique to bypass marketplace security.

Key Points

1. GreedyBear utilized 150 weaponized Firefox extensions, nearly 500 malicious executables, and phishing websites to steal over $1 million.

2. The group employed 'Extension Hollowing,' a technique involving the creation of seemingly legitimate extensions before weaponizing them with malicious code.

3. The operation evolved from the 'Foxy Wallet' campaign, expanding from 40 to over 150 malicious extensions.

4. The attack targeted popular crypto wallets like MetaMask, TronLink, Exodus, and Rabby Wallet, capturing credentials directly from user input fields.

5. Koi Security exposed the campaign, highlighting its scale and coordination in crypto-focused cybercrime.

Description

Cybersecurity firm Koi Security exposed the GreedyBear attack group’s sophisticated operation, utilizing 150 weaponized Firefox extensions, nearly 500 malicious executables, and dozens of phishing websites to steal over $1 million in crypto. The coordinated campaign employed a novel “Extension Hollowing” technique to bypass marketplace security by building legitimate-seeming extension portfolios before weaponizing them with malicious code. Single Server Controls $1M+ Theft Operation The attack g...

>> go to origin page
📱 Full Version
$JUP
$0.4942
+0.08%
$IP
$6.576
+5.82%
$FIL
$2.477
+1.19%

More Reading