MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Crypto theft campaign targets Firefox users with fake wallet extensions
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$72,521.001.00%
  • ethereumEthereum(ETH)$2,126.822.46%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$655.730.68%
  • rippleXRP(XRP)$1.430.50%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$91.250.44%
  • tronTRON(TRX)$0.2844150.08%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.99%
  • dogecoinDogecoin(DOGE)$0.0961493.26%
Crypto NewsBitcoin

Crypto theft campaign targets Firefox users with fake wallet extensions

rahulbadiyafad150c105
Last updated: July 3, 2025 4:43 pm
rahulbadiyafad150c105
Published: 8 months ago
Share

More than 40 fake browser extensions for Mozilla Firefox have been tied to an active cryptocurrency theft campaign, according to a report released Wednesday by cybersecurity firm Koi Security.

Contents
  • Malware leverages deceptive design to gain trust
  • Russian-speaking threat actor believed to be behind the campaign

The widespread phishing operation involves malicious extensions that mimic popular crypto wallet tools like Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, MyMonero, Bitget, and others. Once installed, these fake extensions are designed to steal users’ wallet credentials.

“We’ve identified over 40 extensions connected to this campaign, which remains active and ongoing,” Koi Security stated.

According to the firm, the operation has been running since at least April, with new malicious extensions uploaded as recently as last week. These extensions reportedly harvest wallet credentials directly from compromised websites and send the data to a remote server controlled by the attackers.

Source: SlowMist

Malware leverages deceptive design to gain trust

According to the report, the campaign exploits user trust by mimicking legitimacy through fake ratings, reviews, branding, and functional design. Some of the malicious extensions even displayed hundreds of bogus five-star reviews to appear credible.

These fake extensions used the exact names and logos of the genuine wallet services they impersonated. In several cases, attackers cloned the official open-source code of legitimate extensions, modifying it to include malicious components while maintaining the original functionality.

“This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection.”

Russian-speaking threat actor believed to be behind the campaign

Koi Security noted that while “attribution remains tentative,” several indicators suggest a Russian-speaking threat actor may be responsible. These clues include Russian-language comments embedded in the code, as well as metadata from a PDF file recovered from a command-and-control server linked to the malware campaign.

“While not conclusive, these artifacts suggest that the campaign may originate from a Russian-speaking threat actor group.“

To reduce risk, Koi Security advised users to install browser extensions only from trusted and verified publishers. The firm also emphasized that extensions should be treated like full software applications—recommending the use of allowlists and regular monitoring for unusual behavior or unauthorized updates.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

OpenSea Prepares Massive Token Launch and Airdrop as It Reinvents Its Identity
Vantage
Unraveling Bipolar Disorder: Neurodegeneration in the Paraventricular
Actualités MONDE ENTIER :: XRP ETF Approval Possible, PioneerHash Leads New Global Investment Trend :: WORLD News
Nexo rolls out zero-interest, no-fee crypto credit as lending demand surges – Cryptopolitan
TAGGED:BitcoincryptocurrenciesCybercrimeCybersecurityEthereumFirefoxHackersHacks

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Best Crypto to Buy Now? Bitcoin Just Cleared $109K Resistance
Next Article $SE | ($SE) Trading Report (SE)
© Market Alert News. All Rights Reserved.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Prove your humanity


    Lost your password?

    %d