This dangerous malware disguises itself as a legit browser extension to steal your cash

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Cybersecurity researchers from Trustwave SpiderLabs have discovered a new strain of malware that targets victim’s cryptocurrency wallets. 

Dubbed Rilide, the malware poses as an extension for Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, or Opera.

The malware poses as a legitimate extension for Google Drive, and should people install it on their endpoints, they’d give the malware the ability to monitor their browsing history, grab screenshots, and even inject malicious scripts that would pull all of their money found in cryptocurrency exchanges. 

Forged dialogs

What makes this malware unique is its ability to utilize “forged dialogs” to trick people into giving away their multi-factor authentication keys, and then pull cryptos while operating in the background. If the malware spots that the user has an account on a cryptocurrency exchange, it will try and make a withdrawal request in the background, while presenting the user with a forged device authentication dialog, to get the 2FA code. 

Usually, cryptocurrency exchanges would also notify the users of withdrawal requests via email, which is also something this malware tries to hide. These email confirmations get replaced “on the fly”, the researchers said, as long as the user enters the mailbox using the same web browser. The request email is replaced with a device authorization request, tricking the victim into giving away the 2FA code.

For the researchers, the Rilide stealer is a “prime example” of how malicious browser extensions are getting more sophisticated, and more dangerous. Both businesses and consumers need to remain vigilant, in a time when too much information can dull our senses, the researchers conclude. Not all identities on the internet are legitimate:

“Informational overload can dull our ability to interpret facts accurately and make us more vulnerable to phishing attempts. It is important to remain vigilant and skeptical when receiving unsolicited emails or messages, and to never assume that any content on the Internet is safe, even if it appears to be.”

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games