GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 150 malicious Firefox extensions, nearly 500 malicious executables, and numerous fraudulent websites. They employ techniques such as 'Extension Hollowing' to replace legitimate extensions with malicious versions that capture wallet credentials. The campaign is centralized, with most malicious domains resolving to a single IP address, and it has expanded to target other browsers while utilizing AI-generated code to enhance scalability and evade detection.
What is the primary technique used by the GreedyBear group to steal cryptocurrency credentials from their targets?+
GreedyBear employs a technique called 'Extension Hollowing', where legitimate browser extensions are replaced with malicious versions designed to capture users' cryptocurrency wallet credentials.
What characteristic of GreedyBear's C2 infrastructure can be leveraged by defenders for detection?+
GreedyBear's C2 infrastructure is centralized, with most fraudulent domains resolving to a single IP address. Defenders can implement detection rules based on such infrastructure indicators.