Smart Business Tips
Sign In
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Notification
Everything to know about the Canada Strong Pass
Personal Finance

Everything to know about the Canada Strong Pass

I Thought Refinancing Was Dead—Until I Ran the Numbers
Investing

I Thought Refinancing Was Dead—Until I Ran the Numbers

What Real Estate Investors Miss About Short-Term Capital
Investing

What Real Estate Investors Miss About Short-Term Capital

Meta Adds Copyright Check Into the Reels Composer on Facebook
Social Media

Meta Adds Copyright Check Into the Reels Composer on Facebook

Font ResizerAa
Smart Business TipsSmart Business Tips
  • Home
  • Business
  • Entrepreneurship
  • Contact US
  • Branding
  • Sales
  • Shop
Search
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Sign In Sign In
Follow US
Made by ThemeRuby using the Foxiz theme. Powered by WordPress
Smart Business Tips > Blog > Crypto > Crypto Theft Campaign Hits Firefox Users with Wallet Clones
Crypto

Crypto Theft Campaign Hits Firefox Users with Wallet Clones

Admin45
Last updated: July 3, 2025 10:52 am
By
Admin45
3 Min Read
Crypto Theft Campaign Hits Firefox Users with Wallet Clones
SHARE


Contents
Malware exploits trust through designRussian-speaking threat actor suspected

More than 40 fake extensions for the popular web browser Mozilla Firefox have been linked to an ongoing malware campaign to steal cryptocurrencies, according to a report published Wednesday by cybersecurity firm Koi Security.

The large-scale phishing operation reportedly deploys extensions impersonating wallet tools such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, MyMonero, Bitget and others. Once installed, the malicious extensions are designed to steal users’ wallet credentials.

“So far, we were able to link over 40 different extensions to this campaign, which is still ongoing and very much alive,” the company said.

Koi Security said the campaign has been active since at least April, and the most recent extensions were uploaded last week. The extensions reportedly extract wallet credentials directly from targeted websites and upload them to a remote server controlled by the attacker.

Source: SlowMist

Related: How a simple browser extension prevented an $80K transfer to a malicious wallet

Malware exploits trust through design

Per the report, the campaign leverages ratings, reviews, branding and functionality to gain user trust by appearing legitimate. One of the applications had hundreds of fake five-star reviews.

The fake extensions also featured identical names and logos to the real services they impersonated. In multiple instances, the threat actors also leveraged the official extensions’ open-source code by cloning their applications but with added malicious code:

“This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection.”

Related: Microsoft warns of new remote access trojan targeting crypto wallets

Russian-speaking threat actor suspected

Koi Security said “attribution remains tentative,” but suggested “multiple signals point to a Russian-speaking threat actor.” Those signals include Russian-language comments in the code and metadata found in a PDF file retrieved from a malware command-and-control server involved in the incident:

“While not conclusive, these artifacts suggest that the campaign may originate from a Russian-speaking threat actor group.“

To mitigate risk, Koi Security urged users to install browser extensions only from verified publishers. The firm also recommended treating extensions as full software assets, using allowlists and monitoring for unexpected behavior or updates.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express



Source link

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
Share This Article
Facebook Email Copy Link
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Ad image

You Might Also Like

Traditional Companies Enter the Crypto Treasury Game With BTC, XRP, and SOL Buys
Crypto

Traditional Companies Enter the Crypto Treasury Game With BTC, XRP, and SOL Buys

By
Admin45
July 23, 2025
Grosse Pointe Farms Regulates Crypto ATMs To Stop Scams
Crypto

Grosse Pointe Farms Regulates Crypto ATMs To Stop Scams

By
Admin45
July 16, 2025
Bitcoin Realized Profits Are Still Lower Than 2024 Peaks
Crypto

Bitcoin Realized Profits Are Still Lower Than 2024 Peaks

By
Admin45
July 2, 2025
Santa Rally Could Send Bitcoin Price To 0K By X-Mas Day
Crypto

Santa Rally Could Send Bitcoin Price To $300K By X-Mas Day

By
Admin45
July 12, 2025
Ripple Concludes Pilot In Kenya Using RLUSD
Crypto

Ripple Concludes Pilot In Kenya Using RLUSD

By
Admin45
July 12, 2025
Bitcoin Mempool Is Almost Empty Again — What’s Happening?
Crypto

Bitcoin Mempool Is Almost Empty Again — What’s Happening?

By
Admin45
July 5, 2025

SmartBusinessTips

  • Business Tools & Apps
  • Marketing Strategies
  • Social Media
  • Tech Trends
  • Branding
  • Business
  • Crypto
  • Sales
  • About Us
  • Privacy Policy
  • Member Login
  • Contact Us
  • Business Coaching
  • Business Growth
  • Content Marketing
  • Branding

@Smartbusinesstips Copyright-2025-2027 Content.

Don't not sell my personal information
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up