Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets
Global Security

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

AdminBy AdminJuly 3, 2025No Comments3 Mins Read
Malicious Firefox Extensions
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


03 July 2025Red LakshmananBrowser’s safety / cryptocurrency

A malicious expansion of Firefox

Cybersecurity researchers have found more than 40 malicious browser for Mozilla Firefox, which are designed to steal cryptocurrency wallet, at risk of digital assets of users.

“These extensions represent themselves legal tools for wallet from widely used platforms such as Coinbase, Metamask, Trust Wallet, Phantom, Courtus, Okx, Keplr, Mymonero, Bitget, Leap, Ethereum Calt and Filfox – Note.

A large -scale company is said to have been going on at least April 2025, with the new extension uploaded to the Firefox supplement store recently last week.

Cybersecurity

It was found that the expansion of artificially inflated their popularity was revealed by adding hundreds of 5-star reviews that go far beyond the total number of active attitudes. This strategy is used to give them the illusion of authenticity, and it seems that they are widely accepted and reinforced anything susceptible users before installing them.

Another tactic accepted by the actor threats to enhance confidence, provides for the transfer of these additions as legal wallet tools using the same names and logos.

The fact that some actual extensions were open source allowed the attackers to clone their source code and introduce their own malicious functionality to extract wallet keys and seed phrases from the target sites and select them on a remote server. It was also revealed that the extension of the robbers convey the external IPs of the victims.

Unlike typical phishing scammers who rely on fake sites or emails, these extensions work in the user’s browser – creating them much more difficult to detect or block the traditional final points.

“This low impact approach allowed the actor to maintain the expected user experience while reducing the chances of immediate detection,” Ronneh said.

The presence of Russian language comments in the source code, as well as metadata derived from the PDF file obtained from the command and control server (C2) used for action indicating the Russian -speaking actors threat.

Cybersecurity

All revealed additions, except mymonero wallet, have since been lifted by Mozilla. Last month’s browser manufacturer – Note He developed an “early detection system” to detect and block the extensions of the crysting -snap before gaining popularity among users and used to steal users’ assets by deceiving them in their credentials.

To mitigate the risk provided by such threats, it is recommended to install the extensions only from proven publishers and vet to make sure that they do not silently change their behavior after installation.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.