McAfee Labs has identified a sophisticated cryptocurrency-stealing campaign called Silent Swap that uses malicious browser extensions to intercept and replace wallet addresses during user transactions on Chromium-based browsers.
Key Points
- The Silent Swap campaign uses unsigned installers to deploy a fake "Google Notes" extension that monitors system clipboards for cryptocurrency wallet addresses.
- Attackers utilize a technique called EtherHiding, which leverages blockchain smart contracts to dynamically update command-and-control server domains.
- The malware modifies browser preference files to bypass security verification, allowing the extension to load silently without standard web store approval.
- Affected cryptocurrencies include Bitcoin, Ethereum, Bitcoin Cash, Ripple, Dash, and Solana, with victims reported globally, particularly in India, the U.S., and Brazil.
- Separate malicious extensions, marketed as "VPN Go," were also discovered on Chrome and Firefox stores, exfiltrating sensitive data like passwords and API keys.