Crypto Prices

Cybersecurity Alert: Malicious Browser Extensions Target Cryptocurrency Users

47 minutes ago
1 min read
1 views

Malicious Browser Extensions Targeting Cryptocurrencies

Recent investigations by cybersecurity experts have revealed a troubling scheme involving 19 malicious browser extensions designed to pilfer cryptocurrencies. According to research by Socket, a security firm, these extensions include 18 targeted at Google Chrome and one for Microsoft Edge, identified as having been published or weaponized in the last six months, with origins potentially tracing back to February 2024.

Methods of Operation

The threat actors behind this operation utilized various tactics, including:

  • Creating seemingly legitimate extensions
  • Acquiring existing ones from their original developers before turning them malicious

Out of the 19 extensions identified, 14 were developed by these malicious actors, while the remaining five were purchased from authentic creators.

Notable Malicious Extensions

Among these extensions, “Enable Right Click & Copy — Smart Unlock + OCR” stands out as particularly dangerous, having reached approximately 70,000 users on Chrome before its malicious functions were uncovered. Currently, although the Chrome extension has been removed from the Chrome Web Store, the Edge version still remains in circulation with around 10,000 users.

Capabilities of the Malware

Socket’s research highlights that this malware is capable of dismantling Content Security Policy protections on various websites. Additionally, the investigators have noted that the campaign includes a sophisticated multi-chain cryptocurrency wallet drainer, which targets Ethereum-Virtual-Machine compatible wallets, as well as those on platforms like Solana and Tron.

The malicious extensions manipulate standard features like “Connect Wallet” and “Swap” buttons to reroute users toward fraudulent transaction processes controlled by attackers. Furthermore, the malware implements deceptive tactics aimed at hardware wallet users by presenting convincing phony Ledger and Trezor recovery or update pages to entice victims into divulging their seed phrases.

Broader Impact and Recommendations

This expansive campaign is designed to harvest authenticated sessions and sensitive account details from leading cryptocurrency exchanges such as Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, and Bybit, along with the popular cryptocurrency wallet, MetaMask. Other modules are engineered to hijack Facebook and LinkedIn accounts, siphon browsing history, and utilize ClickFix-style fake browser update prompts.

To mitigate the risks posed by these malicious extensions, Socket strongly recommends that users regularly audit their installed browser extensions and eliminate any that appear suspicious.

Popular