GreedyBear Expands With Malicious Firefox Extensions Draining Crypto Wallets
GreedyBear hackers deploy 150 malicious Firefox extensions, stealing $1M from crypto users. Learn their methods and how to protect assets.
The GreedyBear hacking syndicate has significantly intensified its global cybercrime operations, deploying 150 weaponized Firefox extensions to target cryptocurrency holders—an alarming surge from the 40 malicious add-ons used in earlier campaigns. In just five weeks, these attacks have siphoned more than $1 million from unsuspecting victims.
Investigations reveal that nearly all attack domains are linked to a single IP address, pointing to a highly coordinated criminal infrastructure. The group’s main strategy revolves around producing convincing replicas of legitimate crypto wallet extensions. Initially harmless, these extensions are later updated with hidden malicious code that steals wallet credentials—a sophisticated technique cybersecurity experts call “Extension Hollowing.”
While English-speaking users worldwide have been the primary victims of these Firefox-based attacks, Russian-speaking users have reportedly been targeted with malicious executable files. Losses from these attacks remain undisclosed.
GreedyBear’s modus operandi involves releasing authentic-looking, functional extensions that imitate popular crypto wallets. Once users install them, the extensions are silently updated with code designed to capture and transmit private keys and login details directly to the attackers. This approach allows the malware to evade antivirus detection and remain active within the victim’s browser for extended periods.
Cybersecurity professionals urge cryptocurrency investors to take rigorous precautions: always download wallet software from official vendor websites, confirm authenticity through independent reviews, and consider hardware wallets for storing substantial holdings. If a malicious extension is suspected, it should be removed immediately, followed by changing all related wallet credentials and enabling multi-factor authentication.
The rapid escalation from 40 to 150 malicious extensions reflects a broader shift in cybercrime tactics, where browser vulnerabilities are increasingly exploited for high-value theft. Experts warn that other organized cybercrime networks may adopt similar methods in the near future.
Awareness and prevention remain the best defenses. By understanding these attack vectors and practicing strict digital security habits, cryptocurrency users can greatly reduce their chances of falling victim to such sophisticated schemes.



