Tuesday, December 16, 2025
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

A Russian Hacking Group Is Using Fake Versions of MetaMask to Steal $1M in Crypto

August 10, 2025
in Web3
Reading Time: 5 mins read
0 0
A A
0
Home Web3
Share on FacebookShare on Twitter



In short

Russian hacking group GreedyBear has scaled up its operations and stolen $1 million inside the final 5 weeks.
Koi Safety reported that the group has “redefined industrial-scale crypto theft,” utilizing 150 weaponized Firefox extensions.
This specific ploy entails creating faux variations of broadly downloaded crypto wallets corresponding to MetaMask, Exodus, Rabby Pockets and TronLink.

The Russian hacking group GreedyBear has scaled up its operations in latest months, utilizing 150 “weaponized Firefox extensions” to focus on worldwide and English-speaking victims, in accordance with analysis from Koi Safety.

Publishing the outcomes of its analysis in a weblog, U.S. and Israel-based Koi reported that the group has “redefined industrial-scale crypto theft,” utilizing 150 weaponized Firefox extensions, near 500 malicious executables and “dozens” of phishing web sites to steal over $1 million inside the previous 5 weeks.

Chatting with Decrypt, Koi CTO Idan Dardikman mentioned that the Firefox marketing campaign is “by far” its most profitable assault vector, having “gained them a lot of the $1 million reported by itself.”

This specific ploy entails creating faux variations of broadly downloaded crypto wallets corresponding to MetaMask, Exodus, Rabby Pockets, and TronLink.



GreedyBear operatives use Extension Hollowing to bypass market safety measures, initially importing non-malicious variations of the extensions, earlier than updating the apps with malicious code.

In addition they submit faux critiques of the extensions, giving the misunderstanding of belief and reliability.

However as soon as downloaded, the malicious extensions steal pockets credentials, which in flip are used to steal crypto

Not solely has GreedyBear been in a position to steal $1 million in simply over a month utilizing this technique, however they’ve vastly ramped up the size of their operations, with a earlier marketing campaign–energetic between April and July of this 12 months–involving solely 40 extensions.

The group’s different main assault technique entails nearly 500 malicious Home windows executables, which it has added to Russian web sites that distribute pirated or repacked software program.

Such executables embrace credential stealers, ransomware software program and trojans, which Koi Safety suggests signifies“a broad malware distribution pipeline, able to shifting ways as wanted.”

The group has additionally created dozens of phishing web sites, which fake to supply professional crypto-related providers, corresponding to  digital wallets, {hardware} gadgets or pockets restore providers.

GreedyBear makes use of these web sites to coax potential victims into coming into private knowledge and pockets credentials, which it then makes use of to steal funds.

“It’s price mentioning that the Firefox marketing campaign focused extra international/English-speaking victims, whereas the malicious executables focused extra Russian-speaking victims,” explains Idan Dardikman, talking to Decrypt.

Regardless of the number of assault strategies and of targets, Koi additionally experiences that “nearly all” GreedyBear assault domains hyperlink again to a single IP handle: 185.208.156.66.

In keeping with the report, this handle features as a central hub for coordination and assortment, enabling GreedyBear hackers “to streamline operations.”

Dardikman saidthat a single IP handle “means tight centralized management” reasonably than a distributed community.

“This means organized cybercrime reasonably than state sponsorship–authorities operations usually use distributed infrastructure to keep away from single factors of failure,” he added. “Possible Russian felony teams working for revenue, not state route.”

Dardikman mentioned that GreedyBear is prone to proceed its operations and supplied a number of suggestions for avoiding their increasing attain.

“Solely set up extensions from verified builders with lengthy histories,” he mentioned, including that customers ought to at all times keep away from pirated software program websites.

He additionally advisable utilizing solely official pockets software program, and never browser extensions, though he suggested transferring away from software program wallets if you happen to’re a critical long-term investor.

He mentioned, “Use {hardware} wallets for important crypto holdings, however solely purchase from official producer web sites–GreedyBear creates faux {hardware} pockets websites to steal cost data and credentials.”

Day by day Debrief E-newsletter

Begin on daily basis with the highest information tales proper now, plus authentic options, a podcast, movies and extra.



Source link

Tags: cryptofakeGroupHackingMetaMaskRussianStealVersions
Previous Post

Get More Done With a Touchscreen Chromebook That Travels Light

Next Post

Ethereum Breaks $4K and Analysts Say Remittix Could Outperform ETH by 500% in the Next 6 Months

Related Posts

Bitcoin, Ethereum ETFs Shed $582M in a Day as Institutions Trim Risk
Web3

Bitcoin, Ethereum ETFs Shed $582M in a Day as Institutions Trim Risk

December 16, 2025
Bitcoin’s Retreat to $85,000 Shifts Losses to New Entrants
Web3

Bitcoin’s Retreat to $85,000 Shifts Losses to New Entrants

December 16, 2025
Strategy Adds Nearly a Billion Dollars in Bitcoin for Second Straight Week
Web3

Strategy Adds Nearly a Billion Dollars in Bitcoin for Second Straight Week

December 15, 2025
JPMorgan just crossed a dangerous line with Solana that major banks have strictly avoided until now
Web3

JPMorgan just crossed a dangerous line with Solana that major banks have strictly avoided until now

December 15, 2025
XRP is flooding Ethereum and Solana, but this invisible layer exposes your wallet to a $1.5 billion risk
Web3

XRP is flooding Ethereum and Solana, but this invisible layer exposes your wallet to a $1.5 billion risk

December 15, 2025
Transhumanism Branded a ‘Death Cult’ as Thinkers Clash Over Humanity’s Future
Web3

Transhumanism Branded a ‘Death Cult’ as Thinkers Clash Over Humanity’s Future

December 14, 2025
Next Post
Ethereum Breaks $4K and Analysts Say Remittix Could Outperform ETH by 500% in the Next 6 Months

Ethereum Breaks $4K and Analysts Say Remittix Could Outperform ETH by 500% in the Next 6 Months

BEST BITCOIN MINER OF 2025! | FULL COMPARISON | S19 KPRO 120Th VS S19 J XP 151Th

BEST BITCOIN MINER OF 2025! | FULL COMPARISON | S19 KPRO 120Th VS S19 J XP 151Th

BNB Tracks Bitcoin’s Playbook – Eyes Breakout Toward $1,200

BNB Tracks Bitcoin’s Playbook - Eyes Breakout Toward $1,200

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In