• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Over 40 Fake Firefox Extensions Linked to Cryptocurrency Theft Campaign

user avatar

by Giorgi Kostiuk

6 hours ago


According to a report by Koi Security, over 40 malicious extensions for the Mozilla Firefox browser are linked to an active cryptocurrency theft campaign. These extensions masquerade as cryptocurrency management tools.

Widespread Phishing Campaign

The campaign, active since April this year, uses extensions impersonating popular wallets such as Coinbase, MetaMask, and others. Once installed, these extensions are designed to steal users' credentials. "So far, we were able to link over 40 different extensions to this campaign, which is still ongoing and very much alive," the company stated.

Deception through Design

The campaign leverages fake reviews and ratings to gain user trust. One application had hundreds of fake five-star reviews. The fake extensions also featured identical names and logos to the real services, and in some instances, cloned the official extensions' open-source code while adding malicious code. "This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection."

Suspected Link to Russian-speaking Hackers

Koi Security indicates that attribution remains tentative; however, multiple signs point to a Russian-speaking threat actor. Such signs include Russian-language comments in the code and metadata found in a PDF file from a malware command-and-control server involved in the incident. "While not conclusive, these artifacts suggest that the campaign may originate from a Russian-speaking threat actor group."

Experts urge users to install browser extensions only from verified publishers and to monitor extension behavior closely to mitigate cryptocurrency theft risks.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Ethereum's Challenges and Opportunities: Navigating Growing Competition

chest

Ethereum faces new challenges and competition but continues to be a key player in the Web3 ecosystem.

user avatarGiorgi Kostiuk

S&P 500 and Nasdaq Hit New Records Amid Unexpected Employment Report

chest

US stock markets reach record highs after strong June employment data. Economic changes prompt investors to adjust their bets.

user avatarGiorgi Kostiuk

Bitcoin Reclaims $110,000 Driven by ETF and Trump Policies

chest

Bitcoin has reached the $110,000 level due to institutional investments and Trump’s policies, reaffirming its status as a viable asset class.

user avatarGiorgi Kostiuk

BlackRock BTC ETF Surpasses S&P 500 ETF in Revenue, New Trends in Cloud Mining

chest

BlackRock Bitcoin ETF shows high revenue, while MiningCoop introduces new contract solutions for cloud mining.

user avatarGiorgi Kostiuk

DePIN Expo 2025 in Hong Kong: A New Phase of Blockchain and Physical Integration

chest

DePIN Expo 2025 in Hong Kong discusses the integration of blockchain technologies with physical assets, promising new business models.

user avatarGiorgi Kostiuk

Garlinghouse on Ripple Shares and XRP: Understanding the Distinction

chest

Garlinghouse emphasizes the distinction between XRP and Ripple shares amidst investor confusion.

user avatarGiorgi Kostiuk
dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.