cryptocurrency4 articles
77 Firefox Add-ons Caught Running a Coordinated Crypto Wallet Heist
Forty malicious Firefox extensions have been discovered impersonating legitimate Web3 products like OKX and Rabby Wallet as part of a campaign called "Offside Wallet Theft Factory," believed to have been active since March 2026. The extensions steal cryptocurrency wallet secrets — including recovery phrases and private keys — using methods such as fake wallet pages, hidden malicious code, and exfiltration via Cloudflare Workers and Supabase. Some extensions initially appeared as innocent sports score or utility tools before being repurposed as wallet-stealing malware, with researchers noting that the low cost of repeatedly publishing disposable extensions makes the campaign highly scalable and persistent.
OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps
OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.
1.4 Million Scam Accounts Taken Down in Southeast Asia Crackdown
In a coordinated operation called "Disruption Week," law enforcement agencies including the US Department of Justice and Royal Thai Police, alongside major tech companies such as Meta, Microsoft, and Google, dismantled scam networks operating out of Southeast Asia. The effort resulted in over 1.4 million social media and Microsoft accounts being disrupted, 63 arrests, and more than $3.8 million in cryptocurrency assets frozen. The targeted scam compounds, located in Cambodia, Laos, and Burma, had been trafficking workers under false pretenses and forcing them to carry out large-scale fraud operations against victims in the US and abroad.
Reaper Malware Hits macOS: Steals Passwords, Drains Crypto Wallets, Then Quietly Moves In
A new macOS malware variant called Reaper, an updated version of the SHub stealer, targets users by spoofing trusted domains like Apple, Microsoft, and Google to steal passwords, cryptocurrency wallet credentials, and sensitive files. Unlike earlier versions, it bypasses Apple's Terminal entirely by using macOS Script Editor to execute its malicious payload, circumventing defences added in macOS Tahoe 26.4. The malware also establishes persistent backdoor access by disguising itself as a Google Software Update process, allowing attackers to remotely execute code on compromised machines every 60 seconds.