Threat Intelligence

Takedown of ShieldGuard cryptocurrency scam detailed

Crypto Trading theme with blurred city abstract lights background

Infosecurity Magazine reports that Okta Threat Intelligence and its partners have disrupted the ShieldGuard cryptocurrency scam involving an illicit browser extension that purported to bolster cryptocurrency wallets' phishing defenses but pilfered sensitive user information instead.

Aside from the removal of the extension from the Chrome Web Store, ShieldGuard also had its domains taken down and backend infrastructure deactivated, according to Okta, which also noted prohibiting user sign-in functionality as part of the clampdown. Suspected Russian-speaking threat actors behind ShieldGuard used social media ads, browser extension listings, and an incentive model to lure targets into downloading the malware, which not only extracted wallet addresses and total HTML content across leading crypto platforms but also monitored users across sessions and executed remote code.

Also integrated into ShieldGuard were a custom JavaScript interpreter and other obfuscation techniques that allowed clandestine code delivery and execution. Additional findings revealed ShieldGuard to be associated with the Radex campaign.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds