HomeSecurityLargest GreedyBear attack ever steals $1 million

Largest GreedyBear attack ever steals $1 million

An advanced cybercriminal operation known as GreedyBear has staged one of the most extensive cryptocurrency theft to date, deploying over 650 malicious tools across multiple channels to steal more than $1 million from unsuspecting victims.

See also: Hackers use legitimate drivers to shut down antiviruses

GreedyBear attack

Unlike traditional threat groups that typically specialize in attack methods, GreedyBear has taken an industrial-scale approach, simultaneously operating malicious browser extensions, distributing hundreds of malware executables, and maintaining a sophisticated phishing infrastructure.

The campaign represents a significant escalation in cybercrime operations, utilizing over 150 weaponized Firefox extensions, nearly 500 malicious Windows executables, and dozens of fake websites pretending to be legitimate cryptocurrency services.

What sets GreedyBear apart from conventional cybercriminal operations is its systematic approach to escalating attacks, using artificial intelligence (AI).

Analysis of the campaign code reveals clear AI signatures, allowing attackers to quickly produce a variety of payloads while evading traditional detection mechanisms.

Koi Security researchers identified this development as part of a broader trend where cybercriminals are leveraging advanced AI tools to accelerate the development and execution of attacks. The threat group’s browser extension strategy uses an advanced technique called “ Extension Hollowing ” to bypass market security checks.

See also: Hackers breach corporate systems in 300 seconds

Instead of trying to pass malicious extensions through initial checks, operators first create legitimate publisher profiles by uploading innocent applications like link cleaners and YouTube downloader software.

Largest GreedyBear attack ever steals $1 million
Largest GreedyBear attack ever steals $1 million

After garnering positive reviews and trust from users, they systematically "empty" these extensions, replacing legitimate functionality with credential-harvesting code while maintaining the established reputation.

The weaponized extensions demonstrate remarkable technical sophistication in their credential extraction capabilities . Each malicious extension targets popular cryptocurrency wallets such as MetaMask, TronLink, Exodus , and Rabby Wallet , precisely mimicking their authentic interfaces.

The malware captures wallet credentials directly from user input fields within the extension's pop-up interface, using JavaScript functions that intercept form submissions before they reach legitimate validation processes.

Upon initialization, the extensions perform additional monitoring functions, transmitting the external IP addresses of victims to remote servers for monitoring and potential attacks. This data collection allows operators to create comprehensive victim profiles while maintaining operational security through a distributed infrastructure.

See also: Hackers exploit link-wrapping services to steal Microsoft 365 login credentials

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Code snippets reveal standardized credential extraction routines across extensions, suggesting centralized development protocols that allow for rapid scale-up of malicious operations while maintaining consistency in attack execution.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS