Back to Hub

Russian Hackers Steal $1M via Fake MetaMask Extensions in Industrial-Scale Operation

Imagen generada por IA para: Hackers rusos roban $1 millón con extensiones falsas de MetaMask en operación a gran escala

A Russian cybercriminal group known as GreedyBear has conducted an industrial-scale cryptocurrency theft operation, compromising over $1 million from unsuspecting victims through sophisticated browser extension attacks. Security researchers have uncovered the group's infrastructure distributing 150 weaponized Firefox extensions designed to impersonate the legitimate MetaMask cryptocurrency wallet.

The attack vector represents a significant evolution in crypto-focused malware, with the hackers bypassing Mozilla's extension security protocols through careful obfuscation techniques. The malicious extensions were distributed through:

  1. Fake update portals mimicking official MetaMask channels
  2. Compromised cryptocurrency forums and tutorial sites
  3. Malvertising campaigns targeting DeFi users

Once installed, the extensions performed a multi-stage attack:

  • Intercepted wallet seed phrases during initial setup
  • Replaced legitimate cryptocurrency addresses during transactions
  • Phished for additional credentials through fake authentication popups

'The scale and sophistication of this operation suggests professional cybercriminal organization with substantial resources,' noted blockchain security analyst Mark Chen. 'They've essentially created a counterfeit extension supply chain.'

Parallel to these digital threats, cryptocurrency executives report an alarming rise in physical 'wrench attacks' - real-world robberies targeting high-net-worth individuals in the crypto space. At least one kidnapping per week is now occurring in major crypto hubs, according to industry security reports.

Security Recommendations:

  1. Only install browser extensions from official stores
  2. Verify extension checksums before installation
  3. Use hardware wallets for significant cryptocurrency holdings
  4. Enable multi-factor authentication on all exchange accounts

The GreedyBear operation highlights the increasing professionalization of crypto-focused cybercrime, with attackers now employing software supply chain tactics previously seen in state-sponsored attacks.

Original source: View Original Sources
NewsSearcher AI-powered news aggregation

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.