Blockchain
GreedyBear Campaign Steals $1M With 650 Crypto Attack Tools – Crypto News
A malicious campaign has netted more than $1 million in stolen crypto using a trifecta of attack types through hundreds of browser extensions, websites and malware, says cybersecurity firm Koi Security.
Koi Security researcher Tuval Admoni said on Thursday that the malicious group, which the company dubbed “GreedyBear,” has “redefined industrial-scale crypto theft.”
“Most groups pick a lane — maybe they do browser extensions, or they focus on ransomware, or they run scam phishing sites — GreedyBear said, ‘why not all three?’ And it worked. Spectacularly,” Admoni said.
The types of attacks undertaken by GreedyBear have been used before, but the report highlights that cybercriminals are now deploying a range of complex scams to target crypto users, which Admoni said shows scammers have stopped “thinking small.”
Over 150 fake crypto browser extensions
More than $1 million has reportedly been stolen from cryptocurrency users from over 650 malicious tools specifically targeting crypto wallet users, Admoni said.
The group has published over 150 malicious browser extensions to the Firefox browser marketplace, each designed to impersonate popular crypto wallets such as MetaMask, TronLink, Exodus, and Rabby Wallet.
The malicious actors use an “Extension Hollowing” technique, first creating a legitimate extensions to bypass the marketplaces’ checks to later make them malicious.
Admoni explained that the malicious extensions directly capture wallet credentials from user input fields within fake wallet interfaces.
“This approach allows GreedyBear to bypass marketplace security by appearing legitimate during the initial review process, then weaponizing established extensions that already have user trust and positive ratings.”
Deddy Lavid, CEO of the cybersecurity firm Cyvers, told Cointelegraph that the GreedyBear campaign “shows how cybercriminals are weaponizing the trust users place in browser extension stores. Cloning popular wallet plugins, inflating reviews, and then silently swapping in credential-stealing malware.”
In early July, Koi Security identified 40 malicious Firefox extensions, suspecting Russian threat actors behind what it called the “Foxy Wallet” campaign.
Crypto-themed malware
The second arm of the group’s attacks focuses on crypto-themed malware, of which Koi Security uncovered almost 500 samples.
Credential stealers like LummaStealer specifically target crypto wallet information, while ransomware variants such as Luca Stealer are designed to demand crypto payments.
Most of the malware is distributed through Russian websites offering cracked or pirated software, Admoni said.
A network of scam websites
The third attack vector in the trifecta is a network of fake websites posing as crypto-related products and services.
“These aren’t typical phishing pages mimicking login portals — instead, they appear as slick, fake product landing pages advertising digital wallets, hardware devices, or wallet repair services,” Admoni noted.
Related: North Korean hackers targeting crypto projects with unusual Mac exploit
He said one server acts as a central hub for command-and-control, credential collection, ransomware coordination, and scam websites, “allowing the attackers to streamline operations across multiple channels.”
The campaign also shows signs of AI-generated code, enabling rapid scaling and diversification of crypto-targeting attacks, representing a new evolution in crypto-focused cybercrime.
“This isn’t a passing trend — it’s the new normal,” Admoni warned.
“These attacks exploit user expectations and bypass static defenses by injecting malicious logic directly into wallet UIs,” Lavid said before adding, “This underscores the need for stronger vetting by browser vendors, developer transparency, and user vigilance.”
Magazine: Philippines blocks big crypto exchanges, Coinbase scammer’s stash: Asia Express
-
others1 week ago
Japan Foreign Investment in Japan Stocks up to ¥528.3B in December 12 from previous ¥96.8B – Crypto News
-
Technology1 week agoOnePlus 15R vs Pixel 9a: Which phone is the best buy under ₹50,000? Display, camera, processor and more compared – Crypto News
-
Blockchain5 days agoThis Week in Stablecoins: Winning the Back Office – Crypto News
-
Technology5 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
Technology5 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
Blockchain1 week agoJPMorgan Prepares to Launch First Tokenized Money Market Fund – Crypto News
-
Business5 days ago
XRP Holders Eye ‘Institutional Grade Yield’ as Ripple Engineer Details Upcoming XRPL Lending Protocol – Crypto News
-
others6 days agoAustralian Dollar loses as US Dollar advances before Michigan Sentiment Index – Crypto News
-
Business5 days ago
DOGEBALL Presale: A Boost to Bring P2E Games Back into the Spotlight – Crypto News
-
Technology5 days agoApple iPhone 16 price drops to ₹40,990 in Croma’s Cromtastic December Sale: How the deal works – Crypto News
-
others5 days ago
XRP Holders Eye ‘Institutional Grade Yield’ as Ripple Engineer Details Upcoming XRPL Lending Protocol – Crypto News
-
Blockchain4 days agoLitecoin Follows Bitcoin’s Momentum, But Resistance Looms At $79.60 – Crypto News
-
Technology4 days agoApple iPhone 15 price drops to ₹36,490 in Croma Cromtastic December Sale: How the deal works – Crypto News
-
Blockchain1 week agoBlockchain’s Institutional Future Is Private and Permissioned – Crypto News
-
Business5 days ago
125 Crypto Firms Mount Unified Defense as Banks Push to Block Stablecoin Rewards – Crypto News
-
Technology5 days ago
Michael Saylor Sparks Debate Over Bitcoin’s Quantum Risk as Bitcoiners Dismiss It as ‘FUD’ – Crypto News
-
Cryptocurrency1 week agoCapital gets selective – Blockworks – Crypto News
-
others1 week ago
Low-Fee vs. High-Leverage – How to Choose the Optimal Exchange for Your Trading Strategy? – Crypto News
-
Technology1 week agoUS Puts Tech Deal With UK on Hold – Crypto News
-
Blockchain1 week agoCiti Says Identity Is the New Gatekeeper for Financial Blockchains – Crypto News
-
others1 week agoJapanese Yen strengthens as BoJ rate hike speculation grows – Crypto News
-
Metaverse1 week ago
How companies are using AI to squeeze more from your wallet – Crypto News
-
Blockchain1 week agoBitcoin on Track For 4th Annual Decline Despite Crypto Adoption – Crypto News
-
Cryptocurrency5 days agoIs ETH Ready for Sustained Recovery or Another Rejection Looms? – Crypto News
-
Blockchain4 days agoCrypto Market Sentiment Not Fearful Enough For Bottom: Santiment – Crypto News
-
Blockchain4 days agoCrypto Market Sentiment Not Fearful Enough For Bottom: Santiment – Crypto News
-
Blockchain4 days agoLitecoin Follows Bitcoin’s Momentum, But Resistance Looms At $79.60 – Crypto News
-
Blockchain1 week agoHow Blockchain Works – Crypto News
-
Metaverse1 week agoSpaceX has two aces up its sleeve in the battle to put AI data centers in space – Crypto News
-
Cryptocurrency1 week agoBitcoin and Ethereum Wobble as US Reports Highest Unemployment Rate Since 2021 – Crypto News
-
Cryptocurrency7 days agoWhy quantum computing is becoming a real concern for Bitcoin – Crypto News
-
Blockchain6 days agoMastercard, BlackRock Join Middle East-Focused Blockchain Effort – Crypto News
-
Technology6 days agoFrom chibi to plushie: 7 Must-try AI portraits you can create with GPT Image 1.5 – Crypto News
-
Technology6 days agoFrom chibi to plushie: 7 Must-try AI portraits you can create with GPT Image 1.5 – Crypto News
-
Business6 days ago
Breaking: VanEck Discloses Fees and Staking Details for its Avalanche ETF – Crypto News
-
Blockchain6 days agoCoinbase Launches Service to Help Businesses Create Tokens – Crypto News
-
Cryptocurrency5 days agoBTC at $143K, ETH above $4000: Citi issues bullish price forecasts as crypto market continues to struggle – Crypto News
-
Business5 days ago
Bitcoin Price Alarming Pattern Points to a Dip to $80k as $2.7b Options Expires Today – Crypto News
-
Metaverse5 days agoAI Tool of the Week: Transform marketing concepts instantly. – Crypto News
-
Business5 days ago
Ethereum Faces Selling Pressure as BitMEX Co-Founder Rotates $2M Into DeFi Tokens – Crypto News
-
others5 days agoElliott Wave, seasonality, and cycles indicate more upside – Crypto News
-
others5 days agoElliott Wave, seasonality, and cycles indicate more upside – Crypto News
-
Blockchain5 days agoBlockchain and AI Vibe-Coding To Dethrone Amazon Web Servies: Crypto exec – Crypto News
-
Blockchain5 days agoBanks Need XRP To Be Pricier—Here’s Why A Finance Expert Says So – Crypto News
-
Cryptocurrency4 days agoXRP Could Add Zero If Rally Is Short-Lived – Crypto News
-
Technology3 days agoSamsung Galaxy S25 Ultra price drops to ₹69,999 at Croma Cromtastic December Sale? Here’s how the deal works – Crypto News
-
others1 week agoPound Sterling trades calmly at start of UK data-packed, BoE week – Crypto News
-
Business1 week ago
World’s Highest IQ Holder Projects $100 XRP in 5 Years, What Does He Know? – Crypto News
-
Cryptocurrency1 week ago
XRP News: Ripple’s RLUSD Eyes Wider Adoption as Stablecoin Expands to Coinbase’s L2 Base – Crypto News
-
Technology1 week agoOnePlus 15R and OnePlus Pad Go 2 launching in India tomorrow: How to watch live-stream, expected price, specs and more – Crypto News
