Thursday, November 20, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Crypto Thieves Dubbed ‘GreedyBear’ Run Industrial-Scale Scam – Details

by DigestWire member
August 10, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

A cybercrime group called “GreedyBear” has been accused of stealing over $1 million through what researchers say is one of the most wide-reaching crypto theft operations seen in months.

Reports from Koi Security reveal the group is running a coordinated campaign that mixes malicious browser extensions, malware, and scam websites — all under one network.

Extensions Turned Into Wallet-Stealing Tools

Instead of focusing on just one method, GreedyBear has combined several. According to Koi Security researcher Tuval Admoni, the group has deployed more than 650 malicious tools in its latest push.

This marks a sharp rise from its earlier “Foxy Wallet” operation in July, which involved 40 Firefox extensions.

The group’s tactic, called “Extension Hollowing,” starts with publishing clean-looking Firefox add-ons such as video downloaders or link cleaners.

These extensions, released under fresh publisher accounts, collect fake positive reviews to appear trustworthy. Later, they are swapped for malicious versions impersonating wallets like MetaMask, TronLink, Exodus, and Rabby Wallet.

Once installed, they grab credentials from input fields and send them to GreedyBear’s control servers.

Malware Hidden In Pirated Software

Investigators have also tied nearly 500 malicious Windows files to the same group. Many of these belong to well-known malware families such as LummaStealer, ransomware similar to Luca Stealer, and trojans acting as loaders for other harmful programs.

Distribution frequently occurs through Russian-language websites that host cracked or “repacked” software. Targeting those seeking free software, the attackers reach far beyond the crypto community.

Modular malware was also found by Koi Security, in which operators can add or swap functions without deploying completely new files.


Fake Crypto Services Created To Swipe Data

Based on reports, in addition to the browser attacks and malware, GreedyBear has established fraudulent websites that fake themselves as genuine cryptocurrency solutions.

Some of these are said to offer hardware wallets, and others are fake wallet repair services for devices such as Trezor.

Also on offer are fake wallet apps with good-looking designs that trick users into inputting recovery phrases, private keys, and payment information.

Unlike standard phishing sites that copy exchange login pages, these scam pages look more like product or support portals.

Reports added that some of them remain active and are still collecting sensitive data, while others are on standby for future use.

Investigators found that nearly all domains tied to these operations lead back to a single IP address — 185.208.156.66. This server acts as the campaign’s hub, handling stolen credentials, coordinating ransomware activity, and hosting scam sites.

Featured image from Unsplash, chart from TradingView

Read Entire Article
Tags: BitcoinistBlockchainCoin Surges
Share30Tweet19
Next Post
Why Has Ripple CEO Not Announced XRP Lawsuit Dismissal? Ex-SEC Lawyer Responds to ‘Fake News’ Claims

Why Has Ripple CEO Not Announced XRP Lawsuit Dismissal? Ex-SEC Lawyer Responds to ‘Fake News’ Claims

Ethena Labs’ USDe overtakes rivals as fastest-growing stablecoin, reaching $10B in TVL in just 500 days

Ethena Labs’ USDe overtakes rivals as fastest-growing stablecoin, reaching $10B in TVL in just 500 days

Anna Alarcón, Co-Star of SXSW Winner ‘Mamífera,’ Set for Lead Role in Liliana Torres’ Follow-Up, ‘Climacteric’ (EXCLUSIVE)  

Anna Alarcón, Co-Star of SXSW Winner ‘Mamífera,’ Set for Lead Role in Liliana Torres’ Follow-Up, ‘Climacteric’ (EXCLUSIVE)  

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Lee: Give Doggett the new ball ahead of Boland

Richard Dreyfuss’ Son Ben Details Alleged Estrangement From the Famed Actor

Kelsea Ballerini Walks 2025 CMAs Red Carpet Solo After Chase Stokes Reunion

Lainey Wilson Kicks Off CMAs With Medley Featuring Miranda Lambert and More

BlackRock’s Bitcoin ETF Bleeds Over $500 Million In Its Biggest One-Day Outflow

Malaysia’s National Power Company Loses Over $1.1 Billion to Illegal Crypto Mining

Trending

Will Bitcoin Price Crash to $60K? Peter Brandt Weighs In
Blockchain

Will Bitcoin Price Crash to $60K? Peter Brandt Weighs In

by DigestWire member
November 20, 2025
0

The post Will Bitcoin Price Crash to $60K Peter Brandt Weighs In appeared first on Coinpedia Fintech...

Pi Network Price Prediction 2025, 2026 – 2030: Why Is Pi Coin Dropping?

Pi Network Price Prediction 2025, 2026 – 2030: Why Is Pi Coin Dropping?

November 20, 2025
WINkLink Price Prediction 2025, 2026 – 2030: Is WIN A Good Investment?

WINkLink Price Prediction 2025, 2026 – 2030: Is WIN A Good Investment?

November 20, 2025
Lee: Give Doggett the new ball ahead of Boland

Lee: Give Doggett the new ball ahead of Boland

November 20, 2025
Richard Dreyfuss’ Son Ben Details Alleged Estrangement From the Famed Actor

Richard Dreyfuss’ Son Ben Details Alleged Estrangement From the Famed Actor

November 20, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Will Bitcoin Price Crash to $60K? Peter Brandt Weighs In November 20, 2025
  • Pi Network Price Prediction 2025, 2026 – 2030: Why Is Pi Coin Dropping? November 20, 2025
  • WINkLink Price Prediction 2025, 2026 – 2030: Is WIN A Good Investment? November 20, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.