Russian Hacker Group Steals $1M With Fake Crypto Wallets, Extensions

GreedyBear Steals $1 Million in Crypto by Hijacking Browser Extensions and Spreading Malware Worldwide

  • GreedyBear, a Russian Hacking group, has stolen $1 million in cryptocurrency in five weeks using new attack methods.
  • The group deployed 150 modified Firefox browser extensions to target users worldwide.
  • Attackers created fake versions of popular crypto wallets like MetaMask, Exodus, Rabby Wallet, and TronLink.
  • Besides browser extensions, nearly 500 malicious Windows programs and multiple phishing websites were used.
  • Investigators say the campaign operates from a single IP address, suggesting criminal rather than state-sponsored activity.

GreedyBear, a Russian cybercrime group, has stolen $1 million over the last five weeks, according to research by Koi Security. The group used 150 malicious Firefox browser extensions and other attack methods to target cryptocurrency users internationally.

- Advertisement -

The operation involved fake versions of widely used crypto wallets—including MetaMask, Exodus, Rabby Wallet, and TronLink—disguised as legitimate browser add-ons. Koi Security reported the campaign also used close to 500 harmful Windows executables and dozens of phishing websites to trick victims into giving up their private wallet credentials.

“The Firefox campaign is by far its most lucrative attack vector, having gained them most of the $1 million reported,” said Koi Security CTO Idan Dardikman, as quoted in Decrypt. Attackers used “Extension Hollowing,” a method where harmless extensions are uploaded first, then updated later with harmful code to bypass browser marketplace checks. The group posted fake user reviews to make these add-ons seem trustworthy.

Once a user installs the malicious extension, the software steals wallet credentials, allowing thieves to access and drain cryptocurrency funds. This recent campaign marks a large jump from GreedyBear’s previous attacks; their last major effort used only 40 extensions over several months, compared to 150 in just over a month this time.

GreedyBear’s other techniques included spreading harmful software programs on Russian websites that offer pirated or altered software. These programs contain tools such as credential stealers, Ransomware, and trojans, pointing to a flexible Malware operation.

- Advertisement -

The campaign also ran dozens of phishing sites pretending to be crypto wallet services, repair shops, or hardware device sellers. These websites encouraged users to enter private information, which was used to steal assets. Koi Security traced almost all related web domains to a single IP address: 185.208.156.66.

Dardikman explained that running everything through one central IP suggests a tightly controlled criminal group, rather than a government-backed operation, because state actors usually use distributed networks to avoid single points of failure.

He advised users to install only browser extensions from verified developers and avoid pirated software sites. He also recommended using official wallet software, switching to hardware wallets for significant holdings, and only purchasing devices from official manufacturer websites, since fake hardware wallet sites are part of the scam. More information is available via Koi Security’s detailed report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

CFTC Drops Proposed Ban on Prediction Markets

The US Commodity Futures Trading Commission has withdrawn a proposal that sought to ban...

Kyle Samani Steps Down as Multicoin Capital Managing Director

Kyle Samani, managing director at Multicoin Capital, announced his departure via a post on...

AMD’s Q4 Beat Upended By Tepid Guidance, Stock Dives 17%

AMD stock plummeted over 17% despite beating earnings estimates, as future revenue guidance disappointed...

Bitcoin ETFs Bleed $2.9B as Traders Hedge for Lower Lows

Persistent Bitcoin ETF outflows and massive futures liquidations indicate the market is shedding highly...

Qualcomm’s Earnings to Test Market Sentiment Amid Declines

Qualcomm (QCOM) reports Q1 fiscal 2026 results after market close on February 4, with...
- Advertisement -

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!