{"id":5979,"date":"2025-08-08T10:03:41","date_gmt":"2025-08-08T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/08\/biggest-ever-greedybear-attack-with-650-hacking-tools-stolen-1-million-from-victims\/"},"modified":"2025-08-08T10:03:41","modified_gmt":"2025-08-08T10:03:41","slug":"biggest-ever-greedybear-attack-with-650-hacking-tools-stolen-1-million-from-victims","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/08\/biggest-ever-greedybear-attack-with-650-hacking-tools-stolen-1-million-from-victims\/","title":{"rendered":"Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims"},"content":{"rendered":"<p>    Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cybercriminal operation known as GreedyBear has orchestrated one of the most extensive cryptocurrency theft campaigns to date, deploying over 650 malicious tools across multiple attack vectors to steal more than $1 million from unsuspecting victims.<\/p>\n<p>Unlike traditional threat groups that typically specialize in single attack methods, GreedyBear has adopted an industrial-scale approach, simultaneously operating malicious browser extensions, distributing hundreds of malware executables, and maintaining elaborate phishing infrastructure.<\/p>\n<p>The campaign represents a significant escalation in cybercriminal operations, utilizing over 150 weaponized Firefox extensions, nearly 500 malicious Windows executables, and dozens of fraudulent websites masquerading as legitimate <a href=\"https:\/\/cybersecuritynews.com\/cryptocurrency-payment-gateways\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency services<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPo-a198cZpd3vxa396JB-datZ1a79jctzdL7uQGQnNt-kviByECIjF63oGDecmSLp_fj5m91O94eSpfk7P7Cx9PXgOZWPoh8h20oc5Xv1nNI_ihAdr_XyvkEBB9_jIjBl3DUfRkZA3c9GXNKmwtSM1nmOiPJ4lYfgBwKDFeo0zplO5XYlJp5fx64osqw\/s16000\/Generic%2520extensions%2520uploaded%2520by%2520the%2520attacker%2520before%2520weaponized%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Generic extensions uploaded by the attacker before weaponized (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>All attack components converge on a centralized command-and-control infrastructure, with domains resolving to the IP address 185.208.156.66, enabling streamlined coordination across multiple threat vectors.<\/p>\n<p>What distinguishes GreedyBear from conventional cybercriminal operations is its systematic approach to scaling attacks using artificial intelligence.<\/p>\n<p>Analysis of the campaign\u2019s code reveals clear signatures of AI-generated artifacts, allowing attackers to rapidly produce diverse payloads while evading traditional detection mechanisms.<\/p>\n<p>Koi Security researchers <a href=\"https:\/\/blog.koi.security\/greedy-bear-massive-crypto-wallet-attack-spans-across-multiple-vectors-3e8628831a05\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this evolution as part of a broader trend where cybercriminals leverage advanced AI tooling to accelerate attack development and deployment.<\/p>\n<p>The threat group\u2019s browser extension strategy employs a sophisticated technique termed \u201cExtension Hollowing\u201d to circumvent marketplace security controls.<\/p>\n<p>Rather than attempting to sneak malicious extensions past initial reviews, operators first establish legitimate publisher profiles by uploading innocuous utilities such as link sanitizers and YouTube downloaders.<\/p>\n<p>After accumulating positive reviews and user trust, they systematically \u201chollow out\u201d these extensions, replacing legitimate functionality with credential-harvesting code while preserving the established reputation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-credential-harvesting-mechanisms\"><strong>Advanced Credential Harvesting Mechanisms<\/strong><\/h2>\n<p>The weaponized extensions demonstrate remarkable technical sophistication in their credential extraction capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgEN6Afrx51lvtOL80D0MN5G6C7spf3ySmuHDFu3fjUzpxkL6P-bL_KKKUAL9JSiB9XtXNAP6T0EUrX1_HNZlnS1Uj7rPyNqITbZfZwgXY3psTU9s5cQ037rD356Txy2GTSGxwJWx3YZnktFZvvKJ758Va-5UXtJTXy3gnn2yHOtL4n0nLCdFQSw98B-e8\/s16000\/One%2520of%2520the%2520trojans%2520download%2520page%2520from%2520rsload.net%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">One of the trojans download page from rsload.net (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>Each malicious extension targets popular <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallets<\/a> including MetaMask, TronLink, Exodus, and Rabby Wallet by precisely mimicking their authentic interfaces.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> captures wallet credentials directly from user input fields within the extension\u2019s popup interface, employing JavaScript functions that intercept form submissions before they reach legitimate validation processes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiRARDD4_ebUN2P-mXPz6PP55Vv_Ugj_-JgFqKRYlkEn3X_Vs5ndqHV9xgwn4Ei2g2p4-FVeWe3WSX6h2akXwbODBAIITXjeD23U77VGrqig5sZ5qZpfBmGJKy0VUjI3q66wd9wuuWh1v8S-kRG9_a9F7Qu9PLOhQINEdFDgz1jvQN6eyo5QT18qgdZ4UY\/s16000\/Wallet-repair%2520services%2520claiming%2520to%2520fix%2520Trezor%2520devices%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Wallet-repair services claiming to fix Trezor devices (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>During initialization, the extensions execute additional <a href=\"https:\/\/cybersecuritynews.com\/windows-based-remote-surveillance-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">surveillance<\/a> functions, transmitting victims\u2019 external IP addresses to remote servers for tracking and potential targeting purposes.<\/p>\n<p>This data collection enables operators to build comprehensive victim profiles while maintaining operational security through distributed infrastructure.<\/p>\n<p>The code snippets reveal standardized credential exfiltration routines across all extensions, suggesting centralized development and deployment protocols that enable rapid scaling of malicious operations while maintaining consistency in attack execution.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Equip your SOC with full access to the latest threat data from\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0that can Improve incident response -&gt;\u00a0<strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn_aug&amp;utm_medium=article&amp;utm_campaign=how-to-get-real-time-iocs&amp;utm_content=feeds-cta1&amp;utm_term=050825#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 14-day\u00a0Free\u00a0Trial<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/biggest-ever-greedybear-attack\/\">Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/biggest-ever-greedybear-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims A sophisticated cybercriminal operation known as GreedyBear has orchestrated one of the most extensive cryptocurrency theft campaigns to date, deploying over 650 malicious tools across multiple attack vectors to steal more than $1 million from unsuspecting victims. Unlike traditional threat groups that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5979","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5979"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5979"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5979\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}