CryptoMediaClub
Sunday, December 21, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

GreedyBear Hackers Steal $1M+ in ‘Industrial Scale’ Crypto Theft Using Multi-Vector Attack

08.08.2025
A A
0
120
VIEWS
ShareShare

Cybersecurity firm Koi Security exposed the GreedyBear attack group’s sophisticated operation, utilizing 150 weaponized Firefox extensions, nearly 500 malicious executables, and dozens of phishing websites to steal over $1 million in crypto.

The coordinated campaign employed a novel “Extension Hollowing” technique to bypass marketplace security by building legitimate-seeming extension portfolios before weaponizing them with malicious code.

Single Server Controls $1M+ Theft Operation

The attack group consolidated operations through a single server, controlling command infrastructure across browser extensions, malware payloads, and scam websites.

GreedyBear evolved from the previously identified “Foxy Wallet” campaign involving 40 malicious extensions. They now show massive scale and coordination in crypto-focused cybercrime operations.

The malicious Firefox extensions impersonated popular cryptocurrency wallets, including MetaMask, TronLink, Exodus, and Rabby Wallet, while capturing credentials directly from user input fields.

GreedyBear Hackers Steal $1M+ in 'Industrial Scale' Crypto Theft Using Multi-Vector Attack
Source: Koi Security

Nearly 500 Windows executables spanning multiple malware families targeted victims through Russian websites distributing cracked software, while fake product landing pages advertised fraudulent hardware wallets and repair services.

Security researchers identified clear signs of AI-generated code artifacts throughout the campaign, enabling attackers to scale operations rapidly and evade detection systems.

The infrastructure expansion includes confirmed Chrome extension variants and suggests imminent cross-platform deployment to Edge and other browser ecosystems beyond Firefox.

Extension Hollowing Technique Bypasses Marketplace Security Through Trust Building

GreedyBear pioneered the Extension Hollowing methodology by creating publisher accounts and uploading 5-7 innocuous extensions, such as link sanitizers and YouTube downloaders, with no functional capabilities.

GreedyBear Hackers Steal $1M+ in 'Industrial Scale' Crypto Theft Using Multi-Vector Attack
Source: Koi Security

The attackers posted dozens of fake positive reviews to build credibility ratings before weaponizing established extensions by changing names, icons, and injecting malicious code.

This approach allowed bypassing marketplace security during initial reviews while maintaining positive ratings and user trust from the hollowed extension’s legitimate history.

The weaponized extensions transmitted victim IP addresses during initialization while capturing wallet credentials from pop-up interfaces and exfiltrating data to remote servers.

The campaign originated from the Foxy Wallet operation but evolved beyond the initial 40 malicious extensions to over 150 weaponized Firefox add-ons.

Victims reported substantial losses as extensions maintained expected wallet functionality while secretly transmitting credentials to attacker-controlled infrastructure.

Koi Security confirmed connections to Chrome through a “Filecoin Wallet” extension communicating with the same server.

The group’s systematic approach to marketplace manipulation and trust exploitation created sustainable distribution channels for credential theft operations, which OKX and Microsoft have warned about earlier this year.

Multi-Platform Campaign Coordinates Malware Distribution Through Centralized Infrastructure

The 500 malicious Windows executables encompassed multiple malware families. Distribution occurred through Russian websites hosting cracked and pirated software, targeting users seeking free alternatives to legitimate applications.

Scam websites masqueraded as Jupiter-branded hardware wallets with fabricated UI mockups and wallet repair services claiming to fix Trezor devices.

The fraudulent landing pages collected personal information, wallet credentials, and payment details through convincing product demonstrations and service offerings.

The centralized server infrastructure enabled streamlined operations across credential collection, ransomware coordination, and phishing campaigns while maintaining operational security.

All domains resolved to the single IP address, which creates a unified command-and-control system for the multi-vector attack campaign.

The campaign’s AI-assisted scaling capabilities enabled rapid payload diversification and detection evasion, which is starting to look like the new normal for crypto-focused cybercrime operations.

Legacy security solutions face increasing challenges as attackers leverage sophisticated automation tools to accelerate attack development and deployment cycles.

Recent large-scale incidents include $1 million in YouTube account hijacking scams, $3.05 million phishing losses, and the $4.5 million CrediX exploit that was subsequently recovered through hacker negotiations.

Many experts have criticized the current crypto security landscape for enabling unethical actions, particularly in the negotiation approach.

Speaking with Cryptonews, Circuit CEO Harry Donnelly criticized negotiation-based recovery methods following recent CrediX protocol fund returns, stating that “automated threat response should be standard to ensure assets are kept out of harm’s way, rather than hoping to bargain with bad actors.”

He emphasized that “the CrediX recovery is a rare win in a system that too often leaves users with little recourse.”

This comes as the cumulative total for the first half of 2025 has hit $2.2 billion in losses through 344 incidents only.

The post GreedyBear Hackers Steal $1M+ in ‘Industrial Scale’ Crypto Theft Using Multi-Vector Attack appeared first on Cryptonews.

Share9Tweet6ShareSharePin2

Related Posts

Why LiquidChain’s Layer-3 Architecture Matters for Bitcoin and Solana Users
All news

Why LiquidChain’s Layer-3 Architecture Matters for Bitcoin and Solana Users

21.12.2025
0

LiquidChain has entered the market at a time when traders and developers are increasingly focused on infrastructure rather than short-term...

Read moreDetails
Address Poisoning Scam: One Copy-Paste Mistake Cost a Crypto Trader $50 Million

Address Poisoning Scam: One Copy-Paste Mistake Cost a Crypto Trader $50 Million

21.12.2025
XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?

XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?

20.12.2025
XRP Price Prediction: $2.17 Breakout or $1.77 Retest as Buyers Test Resolve

XRP Price Prediction: $2.17 Breakout or $1.77 Retest as Buyers Test Resolve

20.12.2025
Solana Price Prediction: Why a $2,500 Vision Collides With a $140 Technical Test

Solana Price Prediction: Why a $2,500 Vision Collides With a $140 Technical Test

20.12.2025
Load More
Next Post
Vitalik Warns Corporate ETH Treasuries Could Become ‘Overleveraged Game’ Despite Benefits

Vitalik Warns Corporate ETH Treasuries Could Become ‘Overleveraged Game’ Despite Benefits

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

Do Kwon Extradition Case Sent Back To Lower Court In Montenegro

Do Kwon Extradition Case Sent Back To Lower Court In Montenegro

2 years ago
“First Time Ever”: CFTC Greenlights Spot Crypto Trading on Regulated U.S. Exchanges

“First Time Ever”: CFTC Greenlights Spot Crypto Trading on Regulated U.S. Exchanges

2 weeks ago
The Knowledge of Crowds: How Blockchain May Remodel Medical Analysis

The Knowledge of Crowds: How Blockchain May Remodel Medical Analysis

11 months ago

SEC Appeals Judge Torres’ Decision in Ripple Case: Seeking Clarifications and Resolutions

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?

XRP Price Prediction: $2.17 Breakout or $1.77 Retest as Buyers Test Resolve

Solana Price Prediction: Why a $2,500 Vision Collides With a $140 Technical Test

Bitcoin ETF outflows look terrifying, but a hidden derivatives pattern proves the smart money isn’t actually fleeing

Bitcoin Price Prediction: Fundstrat Tells Clients to Brace for a $60K Bitcoin Correction Next Year

Bitcoin Price Prediction: Fidelity Flags a $65K Bottom – Is the Cycle Breaking?

Trending

Why LiquidChain’s Layer-3 Architecture Matters for Bitcoin and Solana Users
All news

Why LiquidChain’s Layer-3 Architecture Matters for Bitcoin and Solana Users

21.12.2025
0

LiquidChain has entered the market at a time when traders and developers are increasingly focused on infrastructure...

Address Poisoning Scam: One Copy-Paste Mistake Cost a Crypto Trader $50 Million

Address Poisoning Scam: One Copy-Paste Mistake Cost a Crypto Trader $50 Million

21.12.2025
Bitcoin’s inability to reclaim $90,000 exposes a deep structural fracture that could trap investors during the next unwind

Bitcoin’s inability to reclaim $90,000 exposes a deep structural fracture that could trap investors during the next unwind

21.12.2025
XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?

XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?

20.12.2025
XRP Price Prediction: $2.17 Breakout or $1.77 Retest as Buyers Test Resolve

XRP Price Prediction: $2.17 Breakout or $1.77 Retest as Buyers Test Resolve

20.12.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz