{"id":5402,"date":"2025-08-08T17:39:55","date_gmt":"2025-08-08T17:39:55","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5402"},"modified":"2025-08-08T17:39:55","modified_gmt":"2025-08-08T17:39:55","slug":"40-pretend-crypto-pockets-extensions-discovered-on-firefox-market","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5402","title":{"rendered":"40 Pretend Crypto Pockets Extensions Discovered on Firefox Market"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A classy and large-scale cybercrime marketing campaign, named GreedyBear, has been uncovered for stealing at the least 1,000,000 {dollars} from cryptocurrency customers. The analysis, carried out by cybersecurity agency Koi Safety and shared with Hackread.com, reveals a extremely organised operation that goes far past typical <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/online-scams-how-safe-are-websites-you-visit\/\" target=\"_blank\" rel=\"noreferrer noopener\">on-line scams<\/a>.<\/p>\n<p>As an alternative of specializing in a single sort of assault, the criminals behind GreedyBear are utilizing a coordinated mixture of malicious <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/browser-extensions-exploit-chatgpt-gemini-man-in-the-prompt\/\">browser extensions<\/a>, malicious software program, and faux web sites. This technique permits them to assault from a number of angles on the similar time, making their operation extremely efficient.<\/p>\n<h3 id=\"how-they-do-it-three-attack-methods\" class=\"wp-block-heading\"><strong>How They Do It: Three Assault Strategies<\/strong><\/h3>\n<p>One of many essential methods GreedyBear operates is thru malicious browser extensions. The group has created over 150 faux extensions for the Firefox market, pretending to be standard <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/crypto-wallets-2025-balancing-security-convenience\/\" target=\"_blank\" rel=\"noreferrer noopener\">crypto wallets<\/a> like MetaMask, TronLink, Exodus, and Rabby Pockets.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets.png\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"346\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets.png\" alt=\"\" class=\"wp-image-133190\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets.png 720w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-300x144.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-380x183.png 380w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\"\/><\/a><figcaption class=\"wp-element-caption\">Exodus Pockets danger report from Koidex danger engine (Supply: Koi Safety)<\/figcaption><\/figure>\n<\/div>\n<p>The attackers use a intelligent trick referred to as \u201cExtension Hollowing\u201d to evade safety checks. They first add innocent extensions and, after constructing credibility with faux optimistic critiques, they hole out the extensions by altering their names and icons and injecting malicious code, all whereas conserving the optimistic assessment historical past.<\/p>\n<p>The second technique includes nearly 500 malicious packages, or executables, discovered on websites providing pirated software program. These dangerous packages embody <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/infostealers-as-a-service-identity-hacks-record-highs\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential stealers<\/a>, that are designed to steal your login info, and ransomware, which locks your recordsdata and calls for a fee. The number of these instruments exhibits the group isn&#8217;t just a one-trick pony however has a variety of strategies to focus on victims.<\/p>\n<p>Thirdly, the group has arrange dozens of faux web sites that appear to be reputable crypto companies or pockets restore instruments. These websites are designed to trick customers into coming into private info and pockets particulars.<\/p>\n<h3 id=\"the-core-finding\" class=\"wp-block-heading\"><strong>The Core Discovering<\/strong><\/h3>\n<p>A key element Koi Safety\u2019s analysis has revealed is that each one of those assaults, the faux extensions, the malware, and the rip-off web sites, are all linked to a single central server (<code>185.208.156.66<\/code>). This central hub permits the attackers to handle their large-scale operation with nice effectivity.<\/p>\n<p>Researchers be aware that this marketing campaign, which began as a smaller effort often called Cunning Pockets, has now grown into a serious multi-platform risk, with indicators that it might quickly develop to different browsers like Chrome and Edge.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"581\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-1.png\" alt=\"\" class=\"wp-image-133191\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-1.png 700w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-1-300x249.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/New-Threat-GreedyBear-Steals-1M-From-Crypto-Wallets-1-380x315.png 380w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\"\/><\/a><figcaption class=\"wp-element-caption\">Connection graph for 185.208.156.66 (Supply: Koi Safety)<\/figcaption><\/figure>\n<\/div>\n<p>Researchers additionally <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.koi.security\/greedy-bear-massive-crypto-wallet-attack-spans-across-multiple-vectors-3e8628831a05\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">famous<\/a> that one of these large-scale, automated crime is probably going made potential by new AI instruments, making it sooner and simpler than ever for criminals to launch assaults. This new actuality implies that counting on previous safety strategies is now not sufficient to remain secure on-line.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="3RyCne0L1McJYxEWkGGL"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A classy and large-scale cybercrime marketing campaign, named GreedyBear, has been uncovered for stealing at the least 1,000,000 {dollars} from cryptocurrency customers. The analysis, carried out by cybersecurity agency Koi Safety and shared with Hackread.com, reveals a extremely organised operation that goes far past typical on-line scams. As an alternative of specializing in a single [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5404,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[662,215,67,2500,1575,663],"class_list":["post-5402","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-crypto","tag-extensions","tag-fake","tag-firefox","tag-marketplace","tag-wallet"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5402","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5402"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5402\/revisions"}],"predecessor-version":[{"id":5403,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5402\/revisions\/5403"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5404"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5402"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5402"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 15:13:35 UTC -->