Infosecurity-Magazine
Okta Disrupts ShieldGuard Crypto-Stealing Browser Extension
Article Content
Okta has disrupted a malicious Chrome extension named ShieldGuard, which was designed to steal sensitive cryptocurrency data from users. The extension masqueraded as a security tool, claiming to protect crypto wallets from phishing and harmful transactions. It was found in the Chrome Web Store and linked to a Telegram channel with nearly 7,000 followers. ShieldGuard harvested wallet addresses and account data from major crypto platforms like Binance and Coinbase, and also tracked users across browsing sessions. The operation utilized social engineering tactics, including a multi-level marketing scheme that promised cryptocurrency rewards for referrals. Okta collaborated with Google, Cloudflare, and domain registrars to remove the extension and dismantle its infrastructure. The extension employed obfuscation and a custom JavaScript interpreter to bypass Chrome's security measures, enabling remote code execution. The investigation revealed potential links to Russian-speaking operators and another campaign known as Radex.
Key Points: • ShieldGuard was a malicious Chrome extension targeting cryptocurrency users. • The extension harvested sensitive data from major crypto platforms and Google services. • Okta's coordinated takedown involved multiple industry partners to disrupt the operation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.