Infosecurity Magazine reports that Okta Threat Intelligence and its partners have disrupted the ShieldGuard cryptocurrency scam involving an illicit browser extension that purported to bolster cryptocurrency wallets' phishing defenses but pilfered sensitive user information instead.Aside from the removal of the extension from the Chrome Web Store, ShieldGuard also had its domains taken down and backend infrastructure deactivated, according to Okta, which also noted prohibiting user sign-in functionality as part of the clampdown. Suspected Russian-speaking threat actors behind ShieldGuard used social media ads, browser extension listings, and an incentive model to lure targets into downloading the malware, which not only extracted wallet addresses and total HTML content across leading crypto platforms but also monitored users across sessions and executed remote code.Also integrated into ShieldGuard were a custom JavaScript interpreter and other obfuscation techniques that allowed clandestine code delivery and execution. Additional findings revealed ShieldGuard to be associated with the Radex campaign.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




