Dettaglio notizia
| Data | 01/07/2026 |
| Titolo | Silent Swap Browser Extension Hijacks Crypto Wallet Addresses |
| Contesto | Researchers reported an active Silent Swap campaign that distributes a fake "Google Notes" browser extension to steal cryptocurrency by replacing copied wallet addresses with attacker-controlled ones during transactions. The operation uses unsigned .NET and Golang installers to silently sideload the malicious extension into Chromium-based browsers including Chrome, Edge, Brave, and Opera, where it monitors clipboard activity and browser input for wallet strings across multiple blockchains and swaps them in real time. The malware reportedly abuses Chromium trust mechanisms by altering Secure Preferences and related settings files, recalculating integrity values so the extension appears legitimately installed without user approval. Researchers said the campaign also uses EtherHiding-style blockchain-based command-and-control, querying a smart contract through public RPC infrastructure to resolve active C2 domains such as devops-offensive[.]cc and Zebregts[.]com, complicating detection and takedown. The activity has been linked to the CountLoader threat actor, with infections observed globally and a heavier concentration in India, while dynamic per-victim wallet mapping and published hashes, domains, payload URLs, and Bitcoin wallet indicators suggest a broad effort to monetize consumer cryptocurrency transactions. |
| Fonte | https://mallory.ai/stories/019f1d98-6910-746a-8c03-18327effb078 |
| Discussione? | Parliamone sul Forum |