Cybercrime Group GreedyBear Ramps Up $1M in Crypto Heist

TheCryptoTimesPublicado em 2025-08-04Última atualização em 2025-08-08

A cybercrime group known as “GreedyBear,” has stolen over $1 million in cryptocurrency during a multi-faceted, large-scale attack, cybersecurity firm Koi Security discovered.

Unlike most cybercriminals, who focus on one tactic, GreedyBear attacks using three different vectors in tandem, making it an extremely coordinated crime.  These methods are fake browser wallet extensions, crypto-targeting malware, and scam websites.

According to Koi Security researcher Tuval Admoni, “Most groups pick a lane — maybe they do browser extensions, or ransomware, or phishing sites. GreedyBear said, ‘Why not all three?’ And it worked. Spectacularly.” Admoni said the group has used over 650 malicious tools aimed at crypto wallet users, stealing more than $1 million in the process.

Fake Wallet Extensions, Malware, and Scam Sites

The group has published over 150 fake crypto wallet browser extensions on the Firefox marketplace. These copy popular wallets like MetaMask, TronLink, Exodus, and Rabby Wallet. 

At first, the extensions are harmless to pass Firefox’s review process. Once approved and trusted by users, the criminals update them with malicious code to steal wallet passwords and private keys directly from the wallet interface.

GreedyBear has also distributed nearly 500 malware programs aimed at stealing cryptocurrency. They include password stealers such as LummaStealer that steal wallet information, and ransomware such as Luca Stealer that encrypts devices until victims make payments in crypto. Many of these malicious files are spread through Russian websites offering pirated or cracked software.

Their third part is a system of imitation crypto product websites. They are not only imitating login pages, but they are meant to resemble authentic landing pages for digital wallets, hardware devices, or wallet repair services. In actuality, they are decoys to capture sensitive data from unsuspecting visitors.

A Single Control Hub

All of these attacks are traced to a single server and IP address. It controls stolen information, facilitates ransomware requests, and carries scam websites. Experts also think that GreedyBear is employing AI-generated code to facilitate the production of new attacks at a faster rate, making them more difficult to block.

Cybersecurity experts warn this may be the “new normal” in crypto theft, urging stricter extension store security checks, more transparency from developers, and extra caution from users before installing extensions or downloading software.

Also Read: Aave Users Targeted by Scam Ads After $60B Record in Deposits



Leituras Relacionadas

Hot Takes|Why Did the Famous "Tech Lead" Dump All His Bitcoin? The "Investment Whiz Kid" is Here!

**Weekly Spicy Review: Tech Lead's Bitcoin Bust, Reddit Meme, and Trump's Crypto Cash** This week's "Spicy Review" covers three notable incidents from the crypto world. **1. A Tech Lead Learns the Hard Way:** A former Google and Meta technical lead, Patrick Shyu, went viral after revealing he was forced to liquidate all his Bitcoin holdings. He suffered massive losses due to excessive leverage during Bitcoin's sharp decline from $120k to $60k. He shared critical observations: crypto trading often hinges on attention, not fundamentals; Bitcoin lacks a stable source of public focus; the AI boom is diverting capital; and Bitcoin faces structural risks like centralization of code maintenance and quantum computing threats. Despite his short-term exit, he remains a long-term believer. **2. Reddit Roasts the "Investment Whiz":** A popular meme on Reddit's CryptoCurrency subreddit depicted MicroStrategy's Michael Saylor looking down from a balcony. The caption joked about his relentless focus on buying Bitcoin with corporate funds, contrasting with average investors' mundane concerns. The post sparked humorous commentary on his high-risk, high-conviction strategy. **3. Trump's $1.4 Billion Crypto Haul:** The White House's financial disclosure revealed former President Donald Trump earned at least $1.4 billion from cryptocurrency activities in a year, contributing to a total income of over $2.2 billion. This windfall stands in stark contrast to the performance of "TrumpCoin" (officially DJT), which plummeted over 97% from its peak, reportedly causing investor losses exceeding $2 billion. Critics, like California Governor Gavin Newsom, accused Trump of profiting while his supporters suffered losses. The week highlighted a mix of painful lessons learned from leverage, community humor at industry figures, and the stark realities of political figures capitalizing on the crypto market.

Foresight NewsHá 56m

Hot Takes|Why Did the Famous "Tech Lead" Dump All His Bitcoin? The "Investment Whiz Kid" is Here!

Foresight NewsHá 56m

Trading

Spot
活动图片