MyCrypto and PhishFort 49 malicious extensions in the Chrome Web Store that send keys and passwords from cryptocurrency wallets to attackers' servers. The extensions were distributed using phishing advertising methods and presented as implementations of various cryptocurrency wallets. They were based on the code of official wallets but included malicious modifications that sent private keys, recovery codes, and key files.
For some extensions, fake users were artificially used to maintain a positive rating and publish positive reviews. Google removed the specified extensions from the Chrome Web Store within 24 hours after notification. The publication of the first malicious extensions began in February, peaking in March (34.69%) and April (63.26%).
The creation of all extensions is linked to one group of attackers who deployed 14 command servers to manage the malicious code and collect the intercepted data from the extensions. All extensions used standard malicious code but were camouflaged as different products, Ledger (57% of malicious extensions), MyEtherWallet (22%), Trezor (8%), Electrum (4%), KeepKey (4%), Jaxx (2%), MetaMask and Exodus.
During the initial setup of the extension, data was sent to an external server and funds were withdrawn from the wallet after some time.

Source: opennet.ru
