Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silent Swap Crypto Clipper Exploits Fake Extension

Silent Swap Crypto Clipper Exploits Fake Extension

Posted on June 30, 2026 By CWS

Cybersecurity experts have unveiled a new threat targeting cryptocurrency transactions through a malicious browser extension. Dubbed ‘Silent Swap’ by McAfee Labs, this campaign discreetly alters wallet addresses, posing significant risks to crypto users.

How Silent Swap Operates

The Silent Swap campaign is propagated via unsigned installers in both .NET and Golang versions, deploying a harmful Chromium extension disguised as a legitimate ‘Google Notes’ tool. According to a technical report by McAfee Labs, these installers download a ZIP file that serves as the base for the extension. The extension then scans for Chromium-based browsers, terminating their processes to inject itself by altering secure browser files.

This extension, acting as a clipper, intercepts wallet addresses copied to the clipboard, redirecting funds to a wallet controlled by attackers. To achieve this, it asks users for permissions to access the clipboard, URLs, and browsing history. Given the irreversible nature of blockchain transactions, such swaps can lead to permanent financial losses.

Advanced Evasion Techniques

Silent Swap employs a method known as EtherHiding, utilizing the blockchain as a dead drop resolver to update command-and-control server details. This allows attackers to update server information without redeploying malware. The extension also manipulates protected settings in browsers like Chrome and Edge, enabling developer mode through social engineering to facilitate installation.

By recalculating security verification data, the malware deceives browsers into treating the extension as legitimate. This evasion strategy ensures the extension operates silently, bypassing normal installation processes.

Global Impact and Related Threats

Telemetry data indicates a widespread impact, with significant infection rates in India, the U.S., Brazil, Indonesia, and Spain. This campaign exemplifies the evolution of consumer-targeted crypto theft, moving from static attacker addresses to dynamic, server-side mappings.

In a related disclosure, malicious extensions on Chrome and Firefox, presented as ‘VPN Go: Free VPN,’ have been found to include clipboard stealing capabilities. These extensions not only target wallet addresses but also siphon sensitive data like passwords and authentication codes.

Conclusion and Recommendations

Users are advised to remove any suspicious browser extensions immediately and consider any secrets compromised during their activity. As cyber threats become more sophisticated, vigilance and proactive security measures are essential in protecting digital assets.

The Hacker News Tags:Bitcoin, blockchain security, browser extensions, crypto security, Cybersecurity, Ethereum, fake extensions, McAfee Labs, Silent Swap, Solana, VPN Go, wallet theft

Post navigation

Previous Post: Identifying Breaches: How Tier 1 SOC Analysts Decide
Next Post: Supreme Court: Privacy Rights Cover Cellphone Location Data

Related Posts

Iranian Cyber Threats Target U.S. Infrastructure Iranian Cyber Threats Target U.S. Infrastructure The Hacker News
Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts The Hacker News
IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More The Hacker News
New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea The Hacker News
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling The Hacker News
Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Adapt and Persist in Cyberattacks
  • Citrix NetScaler Vulnerability Allows Remote Root Access
  • VINclarity Faces Coordinated Online Reputation Assault
  • SentinelOne Vulnerability Exposes EDR to Malware Risks
  • Critical TP-Link Vulnerabilities Enable Unauthorized Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Adapt and Persist in Cyberattacks
  • Citrix NetScaler Vulnerability Allows Remote Root Access
  • VINclarity Faces Coordinated Online Reputation Assault
  • SentinelOne Vulnerability Exposes EDR to Malware Risks
  • Critical TP-Link Vulnerabilities Enable Unauthorized Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark