Deep Tide TechFlow News, on August 11, according to a report by security company Koi Security, the Russian hacker group GreedyBear successfully stole over 1 million dollars in cryptocurrency through 150 malicious Firefox browser extensions over the past five weeks. The attackers created fake extensions of mainstream cryptocurrency wallets like MetaMask and Exodus, leveraging 'extension hollowing' techniques to bypass app store security checks, embedding malicious code during updates to steal user wallet credentials.
The organization has also deployed nearly 500 malicious Windows programs and multiple phishing websites, showing characteristics of large-scale operations. Security experts recommend that users only use officially verified extensions and suggest migrating important assets to hardware wallets for safekeeping.