AUTO-UPDATED

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

McAfee Labs has identified a sophisticated cryptocurrency-stealing campaign called Silent Swap that uses malicious browser extensions to intercept and replace wallet addresses during user transactions on Chromium-based browsers.

Key Points

  • The Silent Swap campaign uses unsigned installers to deploy a fake "Google Notes" extension that monitors system clipboards for cryptocurrency wallet addresses.
  • Attackers utilize a technique called EtherHiding, which leverages blockchain smart contracts to dynamically update command-and-control server domains.
  • The malware modifies browser preference files to bypass security verification, allowing the extension to load silently without standard web store approval.
  • Affected cryptocurrencies include Bitcoin, Ethereum, Bitcoin Cash, Ripple, Dash, and Solana, with victims reported globally, particularly in India, the U.S., and Brazil.
  • Separate malicious extensions, marketed as "VPN Go," were also discovered on Chrome and Firefox stores, exfiltrating sensitive data like passwords and API keys.

Why it Matters

This campaign demonstrates a significant evolution in cybercrime, moving away from static infrastructure toward resilient, blockchain-based command systems that are difficult to disrupt. Because blockchain transactions are irreversible, these stealthy clipboard-hijacking tactics pose a severe, permanent financial risk to individual cryptocurrency users.
Internet Published by info@thehackernews.com (The Hacker News)
Read original