Home Cyber Security News Silent Swap Crypto Clipper Extension Hijacks Wallet Addresses in Chromium Browsers

Silent Swap Crypto Clipper Extension Hijacks Wallet Addresses in Chromium Browsers

0
Silent Swap Hijacks Wallets

An active malware campaign that steals cryptocurrency by silently replacing wallet addresses during transactions.

The attack uses a malicious browser extension disguised as a harmless “Google Notes” application and targets Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, and Opera.

The campaign is believed to be operated by the same threat actor behind the previously reported CountLoader malware.

Unlike the earlier version, which injected a crypto clipper directly into memory, this new variant relies on a browser extension that quietly intercepts clipboard activity and changes copied cryptocurrency wallet addresses before users paste them into exchanges or wallets.

Because blockchain transactions are irreversible, victims typically cannot recover stolen funds once a transaction is completed.

Silent Swap Hijacks Wallets

The attack begins with an unsigned installer distributed in both .NET and Golang versions. Instead of installing an extension through the official browser stores, the malware directly modifies Chromium configuration files to force-install its own extension.

Our research shows that these are the most affected regions of the globe (Source: mcafee)

The installer targets browser files such as Secure Preferences and Preferences, which normally contain integrity checks designed to detect unauthorized modifications. The malware recalculates these security values after inserting the malicious extension, making the browser believe the changes are legitimate.

For users running older Chromium-based browsers, the extension loads silently. On newer Chrome and Edge versions, Developer Mode must be enabled before the extension becomes active.

Researchers warn that attackers can convince victims to enable this setting through social engineering. The extension disguises itself as a simple note-taking tool named Google Notes. It even provides a basic working interface so users who open it are less likely to become suspicious.

Behind the scenes, however, hidden background scripts continuously monitor clipboard activity and browser pages. These permissions allow it to monitor cryptocurrency transactions across virtually any website.

This image shows the malicious extension at the center of this campaign (Source: mcafee)

One of the campaign’s most advanced features is its use of blockchain technology to hide its command-and-control (C2) infrastructure.

Instead of storing a hardcoded C2 domain inside the malware, the extension contacts a public Ethereum Remote Procedure Call (RPC) endpoint and queries a smart contract. The smart contract returns an encoded value that is decoded into the active attacker-controlled domain at runtime.

Researchers observed domains such as Zebregts[.]com and devops-offensive[.]cc being resolved during analysis.

This technique, commonly known as EtherHiding, allows attackers to change their backend infrastructure simply by updating a smart contract instead of modifying the malware itself.

As a result, traditional domain-based detection and takedown efforts become significantly more difficult.

Telemetry collected by McAfee shows infections worldwide, with India experiencing the highest concentration of affected systems. Researchers believe the campaign targets cryptocurrency users opportunistically rather than focusing on any specific region.

The installer also includes several stealth techniques. It deletes itself after installation, embeds configuration data directly inside the executable, supports both .NET and Golang variants, and recalculates browser integrity signatures using machine-specific identifiers to avoid browser security warnings.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version