As cited
Copy frozen at (site build).
threat intel
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Researchers at McAfee Labs discovered an active campaign distributing a malware browser extension called Silent Swap that intercepts cryptocurrency transactions and replaces wallet addresses with attacker-controlled ones. The malware is deployed via unsigned installers in .NET and Golang variants, masquerading as a Google Notes extension to evade detection.
Why it matters: Cryptocurrency users and exchanges are at risk of losing funds through address substitution attacks; practitioners should alert users to verify extension sources and implement browser security policies blocking unsigned extensions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Researchers at McAfee Labs discovered an active campaign distributing a malware browser extension called Silent Swap that intercepts cryptocurrency transactions and replaces wallet addresses with attacker-controlled ones. The malware is deployed via unsigned installers in .NET and Golang variants, masquerading as a Google Notes extension to evade detection.
Why it matters: Cryptocurrency users and exchanges are at risk of losing funds through address substitution attacks; practitioners should alert users to verify extension sources and implement browser security policies blocking unsigned extensions.
- Source published
- First seen by Cybersecurity Tracker