Author

Topic: 49 chrome extensions caught hijacking crypto wallets (Read 88 times)

hero member
Activity: 1680
Merit: 655
ano masasabi nyo dito mukhang nauuso nanaman yung mga hijacking ngayon. base sa kanilang suggestions wag gumamit nang browser based wallet or yung mga wallet na naka plugin sa browser. maaring gumamit lamang nang hardware wallet or stand alone wallet..
ano nanaman kaya dahilan nila ei napakababa nang market ngayon.

Isa lang masasabi ko dito na kapag Google product user ka  kailangan dapat maging cautious ka when it comes to their apps as literally any developer can upload and make their apps available in Google from Chrome extenstions to Google Playstore lahat ng products nila kung saan pwede ka mag install/download ng apps ay pwedeng pag-mulan ng malicious software and adware, other than that may mga clone or duplicate apps kung tawagin na sikat gamitin sa mga banking apps and wallet apps for phishing purposes.

New Google Android Malware Warning Issued To 8 Million Play Store Users

Google’s Android Play Store is increasingly under fire for allowing malware ridden apps to plague its users. But another warning has been issued to Android users after researchers at ESET discovered a year-long campaign that saw 8 million installs of adware delivered through 42 apps.

So before you download anything from Google's products I would advise to check reviews, star rating, number of downloads kasi isa lang ito sa mga paraan para makita mo if yung app na ito ay makakapagtiwalaan or dapat iwasan at i-report para na din makatulong sa pag-tanggal sa app na ito. Google is doing a pretty bad job at screening apps going through their app market kaya mas mabuti pang maging maingat tayo lalong lalo na sa mga panahon na ito na sumisikat lalo ang cryptocurrency dahil dito dumadami yung mga threats online.
member
Activity: 154
Merit: 10
Quote
Recently, Google has removed malicious 49 Chrome browser extensions from its web store that pretended as cryptocurrency wallets. The extensions were caught hijacking users' wallets by containing malicious code to phish and steal sensitive information and then empty all the cryptocurrencies from the wallets.

Fortunately, the extensions have been identified by the researchers from MyCrypto and PhishFort. MyCrypto is an open-source tool to interact with the blockchain, while PhishFort sells anti-phishing protection. They believe that the extensions were potentially the work of Russian threat actors.

How does it work?

The extensions were phishing for sensitive information such as mnemonic phrases, private keys, and Keystore files, explained by Harry Denley, the Director of Security at MyCrypto. He also mentioned that the extensions would send an HTTP POST request to its backend which leads to the bad actors being able to empty the wallets once users have entered the sensitive information.
Quote

ano masasabi nyo dito mukhang nauuso nanaman yung mga hijacking ngayon. base sa kanilang suggestions wag gumamit nang browser based wallet or yung mga wallet na naka plugin sa browser. maaring gumamit lamang nang hardware wallet or stand alone wallet..
ano nanaman kaya dahilan nila ei napakababa nang market ngayon.
Jump to: