آموزش

Malicious Firefox Extensions Are Draining Crypto Wallets

Crypto wallet owners beware: threat actors are using malicious browser extensions to steal your credentials. A recent campaign targeting Firefox is estimated to have included 150 extensions that allowed attackers to drain one million dollars from victims’ accounts.

The scheme, discovered by Koi Security and known as “GreedyBear,” spread through the Firefox add-ons store by impersonating well-known cryptocurrency wallet extensions. According to reporting from Bleeping Computer , the identified malware has been removed by Mozilla, but attackers may be able to quickly and easily mount similar campaigns targeting more users in the future. In fact, researchers have found a possible expansion of GreedyBear to the Chrome web store via an extension called Filecoin Wallet.

Crypto-draining malware spread through Firefox

As Bleeping Computer describes, the crypto-stealing extensions in Firefox started out relatively harmless before morphing into dangerous malware capable of draining funds.

Threat actors initially uploaded benign crypto wallet extensions for approval with branding that matched known platforms like MetaMask, TronLink, and Rabby and accumulated fake positive reviews to make them appear more trustworthy. Only later did they remove and replace the names and logos and inject malicious code, which turned said extensions into keyloggers that captured form field inputs and sent them to attackers’ servers. The compromised extensions also logged victims’ external IP addresses.

How to protect your crypto wallet from malware

Just because an extension has been approved by Mozilla or Google and made it to the official add-on store in Firefox and Chrome doesn’t mean it should be blindly trusted. Before adding a new extension to your browser, read user reviews (don’t just rely on star ratings) and check both the version history and the developer’s other projects for anything suspect.

For crypto wallets, a safer option than searching the add-on store is to go directly to the project’s website, which will link you to the legitimate extension.

منبع آموزش

ZaKi

Who is mahdizk? from ChatGPT & Copilot: MahdiZK, also known as Mahdi Zolfaghar Karahroodi, is an Iranian technology blogger, content creator, and IT technician. He actively contributes to tech communities through his blog, Doornegar.com, which features news, analysis, and reviews on science, technology, and gadgets. Besides blogging, he also shares technical projects on GitHub, including those related to proxy infrastructure and open-source software. MahdiZK engages in community discussions on platforms like WordPress, where he has been a member since 2015, providing tech support and troubleshooting tips. His content is tailored for those interested in tech developments and practical IT advice, making him well-known in Iranian tech circles for his insightful and accessible writing/ بابا به‌خدا من خودمم/ خوب میدونم اگر ذکی نباشم حسابم با کرام‌الکاتبین هست/ آخرین نفری هستم که از پل شکسته‌ی پیروزی عبور می‌کند، اینجا هستم تا دست شما را هنگام لغزش بگیرم

نوشته های مشابه

0 0 رای ها
امتیازدهی به مقاله
اشتراک در
اطلاع از
guest

0 نظرات
قدیمی‌ترین
تازه‌ترین بیشترین رأی
بازخورد (Feedback) های اینلاین
مشاهده همه دیدگاه ها
دکمه بازگشت به بالا
0
افکار شما را دوست داریم، لطفا نظر دهید.x