Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silent Swap Crypto Clipper Exploits Fake Extension

Silent Swap Crypto Clipper Exploits Fake Extension

Posted on June 30, 2026 By CWS

Cybersecurity experts have unveiled a new threat targeting cryptocurrency transactions through a malicious browser extension. Dubbed ‘Silent Swap’ by McAfee Labs, this campaign discreetly alters wallet addresses, posing significant risks to crypto users.

How Silent Swap Operates

The Silent Swap campaign is propagated via unsigned installers in both .NET and Golang versions, deploying a harmful Chromium extension disguised as a legitimate ‘Google Notes’ tool. According to a technical report by McAfee Labs, these installers download a ZIP file that serves as the base for the extension. The extension then scans for Chromium-based browsers, terminating their processes to inject itself by altering secure browser files.

This extension, acting as a clipper, intercepts wallet addresses copied to the clipboard, redirecting funds to a wallet controlled by attackers. To achieve this, it asks users for permissions to access the clipboard, URLs, and browsing history. Given the irreversible nature of blockchain transactions, such swaps can lead to permanent financial losses.

Advanced Evasion Techniques

Silent Swap employs a method known as EtherHiding, utilizing the blockchain as a dead drop resolver to update command-and-control server details. This allows attackers to update server information without redeploying malware. The extension also manipulates protected settings in browsers like Chrome and Edge, enabling developer mode through social engineering to facilitate installation.

By recalculating security verification data, the malware deceives browsers into treating the extension as legitimate. This evasion strategy ensures the extension operates silently, bypassing normal installation processes.

Global Impact and Related Threats

Telemetry data indicates a widespread impact, with significant infection rates in India, the U.S., Brazil, Indonesia, and Spain. This campaign exemplifies the evolution of consumer-targeted crypto theft, moving from static attacker addresses to dynamic, server-side mappings.

In a related disclosure, malicious extensions on Chrome and Firefox, presented as ‘VPN Go: Free VPN,’ have been found to include clipboard stealing capabilities. These extensions not only target wallet addresses but also siphon sensitive data like passwords and authentication codes.

Conclusion and Recommendations

Users are advised to remove any suspicious browser extensions immediately and consider any secrets compromised during their activity. As cyber threats become more sophisticated, vigilance and proactive security measures are essential in protecting digital assets.

The Hacker News Tags:Bitcoin, blockchain security, browser extensions, crypto security, Cybersecurity, Ethereum, fake extensions, McAfee Labs, Silent Swap, Solana, VPN Go, wallet theft

Post navigation

Previous Post: Identifying Breaches: How Tier 1 SOC Analysts Decide
Next Post: Supreme Court: Privacy Rights Cover Cellphone Location Data

Related Posts

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign The Hacker News
Node.js Exploited in Sophisticated Cyber Attacks Node.js Exploited in Sophisticated Cyber Attacks The Hacker News
Silver Fox Targets India and Russia with ABCDoor Malware Silver Fox Targets India and Russia with ABCDoor Malware The Hacker News
Russian Hackers Exploit OAuth and WhatsApp for Cyber Attacks Russian Hackers Exploit OAuth and WhatsApp for Cyber Attacks The Hacker News
AI-Driven Ransomware Attack Exploits Langflow Vulnerability AI-Driven Ransomware Attack Exploits Langflow Vulnerability The Hacker News
ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Jev AI Stores Exploit Users with Costly Access
  • Microsoft SharePoint Vulnerability Heightens Security Risks
  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Jev AI Stores Exploit Users with Costly Access
  • Microsoft SharePoint Vulnerability Heightens Security Risks
  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark