GreedyBear Steals $1M in Crypto Using 150+ Malicious Firefox Wallet Extensions
More than 150 malicious extensions for the Firefox marketplace have been used by a recently identified campaign called GreedyBear to steal more than $1 million in digital assets by impersonating well-known cryptocurrency wallets.
According to Tuval Admoni, a researcher from Koi Security, the released browser add-ons pose as a variety of different programs, including MetaMask, TronLink, Exodus, and Rabby Wallet.
The adoption of a method known as Extension Hollowing by the threat actor to get over Mozilla's security measures and take advantage of user trust is what makes the activity noteworthy. Note that Lukasz Olejnik, a security researcher, initially reported on some of the campaign's elements last week.
According to a research released Thursday by Admoni, instead of attempting ...

